Compliance-native.
Built around your regulations.
WeVerify is not compliance-adjacent, it is compliance-native. Multi-jurisdiction compliant. eIDAS 2.0 compliant trust service. GDPR by architecture. Built from day one around the frameworks your organisation already answers to, not retrofitted on top of a generic platform.
Certifications & frameworks
Every framework that governs what WeVerify does.
πͺπΊ eIDAS 2.0, QTSP
WeVerify is eIDAS 2.0 compliant, with signatures recognised across all 27 EU member states, plus UK, US (ESIGN/UETA), and Switzerland (ZertES). Biometric verification is required at every signing event.
π Multi-Jurisdiction Compliant
Compliant with eIDAS 2.0 (EU), UK Electronic Signatures Regulations, US ESIGN Act & UETA, and Swiss ZertES. Valid for cross-border transactions across all supported jurisdictions.
π GDPR, Privacy by architecture
Raw biometric data never leaves the user's device. We process cryptographic proofs only. No biometric database exists. This is Article 25 privacy by design, a technical architecture decision, not a policy document.
π¬π§ UK DIATF
Aligned with the UK Digital Identity and Attributes Trust Framework. Signatures produced through WeVerify are valid under UK electronic identification and trust services law.
πΊπΈ US ESIGN & UETA
Electronic signatures meet the US Electronic Signatures in Global and National Commerce Act and state-level UETA, making them legally binding for transactions governed by US law.
π¨π Swiss ZertES
Qualified e-signatures are compliant with Swiss federal law (ZertES), applicable for financial services, corporate transactions, and contracts with Swiss law governing clauses.
π€ EU AI Act, Art. 13
WeVerify's e-Seal supports AI Act Article 13 data provenance requirements for high-risk AI systems, creating a cryptographic record of training data state and lineage.
π± DSA & Online Safety Act
Age verification product satisfies EU DSA and UK OSA age assurance requirements, privacy-first, technically reliable, and no personal data retained after the check.
π ISO/IEC 27001
Information security management practices aligned with ISO/IEC 27001 principles. Full audit trail logging for every verification, signature, and seal event. Formal certification in progress.
Platform comparison
One platform. What usually requires three vendors.
| Capability | WeVerify | Typical IDV vendor | Typical e-sign vendor | Typical age vendor |
|---|---|---|---|---|
| NFC passport identity verification | β Core workflow | ~ Some | β Not offered | ~ Step-up only |
| Biometric deepfake-certified liveness | β ISO 30107-3 | β Standard | β Not offered | ~ Some |
| eIDAS 2.0 Qualified Biometric Signature | β QTSP supervised | β Not offered | ~ Some vendors | β Not offered |
| eIDAS 2.0 Qualified e-Seal | β Qualified | β Not offered | β Not offered | β Not offered |
| Business verification (KYB) | β Real-time registries | ~ Some | β Not offered | β Not offered |
| Identity-gated sealed video call | β Notarial grade | β Not offered | β Not offered | β Not offered |
| Biometric age verification | β DSA & OSA compliant | ~ Some | β Not offered | β Core workflow |
| Multi-jurisdiction compliance | β Active | β Not typical | ~ Some vendors | β Not typical |
| GDPR privacy by architecture | β No biometric database | ~ Policy-based | ~ Policy-based | ~ Varies |
| Reusable verified identity | β Cross-service | ~ Some | β Not offered | β Not offered |
| Single API for all capabilities | β One integration | β IDV only | β Signing only | β Age only |
Compliance questions?
Talk to our team.
We can map WeVerify's certifications to your specific regulatory obligations, whether eIDAS, WMO, DSA, AMLD6, or AI Act. Book a compliance call.
