Trust & Safety

Security & Compliance

Enterprise-grade security infrastructure underpinning every AyeFace transaction.

Full technical security: GitHub → | Technology stack: GitHub →

🇪🇺

GDPR

General Data Protection Regulation. Full compliance for all EU data subjects including rights of access, erasure, portability, and consent withdrawal.

🇲🇾

PDPA (Malaysia)

Personal Data Protection Act 2010. Consent-first biometric enrollment, data minimisation, and subject access request handling.

🇸🇬

PDPA (Singapore)

Personal Data Protection Act 2012 (amended 2021). Mandatory breach notification, data portability obligation, and enhanced consent framework for biometric data.

🇵🇭

DPA (Philippines)

Data Privacy Act of 2012 (Republic Act 10173). NPC-registered data processing with explicit consent for sensitive personal information including biometrics.

🇹🇭

PDPA (Thailand)

Personal Data Protection Act B.E. 2562 (2019). Explicit consent for biometric data as a sensitive data category, data subject rights, and cross-border transfer controls.

🇻🇳

PDPD (Vietnam)

Personal Data Protection Decree 13/2023/ND-CP. Biometric data classified as sensitive, mandatory impact assessments, and prior consent for collection and processing.

🇮🇩

UU PDP (Indonesia)

Personal Data Protection Law No. 27/2022. Explicit consent for biometric and sensitive data, mandatory DPO appointment, and two-year compliance transition period.

🇧🇳

PDPO (Brunei)

Personal Data Protection Order 2021. Consent-based processing, data subject access and correction rights, and cross-border transfer obligations.

🇰🇭

Cambodia

Operating under applicable ASEAN data governance frameworks and Cambodia's e-Commerce Law pending a dedicated personal data protection law. Consent-first practices applied.

🇱🇦

Laos

Operating under Laos' Electronic Data Protection provisions and ASEAN regional frameworks pending comprehensive data protection legislation. Consent-first practices applied.

🔐

End-to-End Encryption

All transactions and biometric templates are encrypted in transit (TLS 1.3) and at rest (AES-256). Raw facial images are never stored.

🏦

Payment Network Compliance

Compliant with Visa, Mastercard, and PayNet security standards. Tokenized payment credentials — no raw card data stored.

☁️

Cloud Infrastructure

Multi-tenant cloud infrastructure with regional data residency options. 99.9% uptime SLA. Auto-scaling, DDoS protection, and WAF.

🔍

Audit Trails

Immutable audit logs for all transactions, biometric events, and admin actions. Tamper-evident logging for compliance and forensics.

🎯

ISO/IEC 30107-3 Liveness Detection

Presentation Attack Detection certified to ISO/IEC 30107-3. Active liveness check prevents photo, video, and mask spoofing — all biometric enrollment and authentication is compliant with this standard.

🏢

SOC 2-Aligned Infrastructure Controls

Infrastructure and operations aligned to SOC 2 Trust Service Criteria covering Security, Availability, and Confidentiality. Regular penetration testing, role-based access controls, and documented incident response procedures.

🛡

Security Disclosure

Discovered a security vulnerability? We take all reports seriously and aim to respond within 24 hours.

Report a Vulnerability