Compliance-native.
Built around your regulations.
WeVerify is not compliance-adjacent, it is compliance-native. Multi-jurisdiction compliant. eIDAS 2.0 compliant trust service. GDPR by architecture. Built from day one around the frameworks your organisation already answers to, not retrofitted on top of a generic platform.
Certifications & frameworks
Every framework that governs what WeVerify does.
πͺπΊ eIDAS 2.0, QTSP
WeVerify is eIDAS 2.0 compliant, with signatures recognised across all 27 EU member states, plus UK, US (ESIGN/UETA), and Switzerland (ZertES). Biometric verification is required at every signing event.
π Multi-Jurisdiction Compliant
Compliant with eIDAS 2.0 (EU), UK Electronic Signatures Regulations, US ESIGN Act & UETA, and Swiss ZertES. Valid for cross-border transactions across all supported jurisdictions.
GDPR, Privacy by architecture
Raw biometric data never leaves the user's device. We process cryptographic proofs only. No biometric database exists. This is Article 25 privacy by design, a technical architecture decision, not a policy document.
π¬π§ UK DIATF
Aligned with the UK Digital Identity and Attributes Trust Framework. Signatures produced through WeVerify are valid under UK electronic identification and trust services law.
πΊπΈ US ESIGN & UETA
Electronic signatures meet the US Electronic Signatures in Global and National Commerce Act and state-level UETA, making them legally binding for transactions governed by US law.
π¨π Swiss ZertES
Qualified e-signatures are compliant with Swiss federal law (ZertES), applicable for financial services, corporate transactions, and contracts with Swiss law governing clauses.
π€ EU AI Act, Art. 13
WeVerify's e-Seal supports AI Act Article 13 data provenance requirements for high-risk AI systems, creating a cryptographic record of training data state and lineage.
π± DSA & Online Safety Act
Age verification product satisfies EU DSA and UK OSA age assurance requirements, privacy-first, technically reliable, and no personal data retained after the check.
π ISO/IEC 27001
Information security management practices aligned with ISO/IEC 27001 principles. Full audit trail logging for every verification, signature, and seal event. Formal certification in progress.
Platform comparison
One platform. What usually requires three vendors.
| Capability | WeVerify | Typical IDV vendor | Typical e-sign vendor | Typical age vendor |
|---|---|---|---|---|
| NFC passport identity verification | β Core workflow | ~ Some | β Not offered | ~ Step-up only |
| Biometric deepfake-certified liveness | β ISO 30107-3 | β Standard | β Not offered | ~ Some |
| eIDAS 2.0 Qualified Biometric Signature | β QTSP supervised | β Not offered | ~ Some vendors | β Not offered |
| eIDAS 2.0 Qualified e-Seal | β Qualified | β Not offered | β Not offered | β Not offered |
| Business verification (KYB) | β Real-time registries | ~ Some | β Not offered | β Not offered |
| Identity-gated sealed video call | β Notarial grade | β Not offered | β Not offered | β Not offered |
| Biometric age verification | β DSA & OSA compliant | ~ Some | β Not offered | β Core workflow |
| Multi-jurisdiction compliance | β Active | β Not typical | ~ Some vendors | β Not typical |
| GDPR privacy by architecture | β No biometric database | ~ Policy-based | ~ Policy-based | ~ Varies |
| Reusable verified identity | β Cross-service | ~ Some | β Not offered | β Not offered |
| Single API for all capabilities | β One integration | β IDV only | β Signing only | β Age only |
Compliance questions?
Talk to our team.
We can map WeVerify's certifications to your specific regulatory obligations, whether eIDAS, WMO, DSA, AMLD6, or AI Act. Book a compliance call.
