Security and compliance

The answers, before you have to ask for them.

Most vendor security pages are adjectives. This one is the actual answers, including the ones that are not finished yet. If your questionnaire asks something that is not here, ask us directly and we will answer it in writing.

DOES FUZZY HOLD A FACE IMAGE?

Yes, one. It is the badge photo.

DOES OUR SCHOOL HOLD ANY?

No. Nothing sensitive reaches you.

A BIRTH DATE, OR A FACE TEMPLATE?

Neither. An 18+ signal, and a photo.

WHERE DOES IT LIVE?

AWS, United States only.

Data

What we keep. What we refuse to keep.

Minimisation as a list rather than a policy paragraph. This is the whole set, and the right-hand column is the one that matters in a review.

What Fuzzy stores

THE FIELDS REVIEWERS ASK ABOUT MOST

  • Given name and family name
  • An 18+ age band, established at verification
  • Verification status and its dates
  • City, region and country, taken from the document
  • The still photo from your verification, which becomes your badge photo, plus your email address
  • A one-way lookup hash, so a relying party can ask about a person without naming them

On the photo, precisely. In the standard verification flow, the still image captured during your verification becomes your badge photo. It is a photograph, not a faceprint: no face template or embedding is stored for a verified member, and the face match itself runs at Incode against Incode's own record, never against our copy. Anyone holding your badge link can load that photo, and messaging apps fetch it to draw a link preview, which is what makes a badge readable by a person at all. Age is held as an affirmative 18-plus signal; your birth date is read during verification and is not kept in the credential.

What Fuzzy never stores

NOT IN THE DATABASE, BY ARCHITECTURE

  • ID documents, or any image of one
  • A face template or biometric embedding from the verification pipeline, or the liveness video
  • Social security numbers
  • Home addresses
  • ID or document numbers
  • A reason, on anything we report to a partner or an institution
  • ID document numbers, or any document image
  • Personal data in application event logs

Age is held as an affirmative 18-plus signal and nothing more. Under-18 is deliberately not one of our outcome states, because recording it would mean holding a sensitive fact about a minor.

Certifications

Whose certifications are whose.

Plenty of vendors quote their provider's certificates as though they were their own. We are going to be exact about this, because your reviewer will check.

Held by Incode Technologies

OUR IDENTITY ENGINE · NOT FUZZY

  • SOC 2 Type II
  • ISO/IEC 27001, information security management
  • ISO/IEC 30107-3, presentation attack detection
  • ISO/IEC 42001, AI management systems
  • Kantara IAL2 trust mark under NIST 800-63A
  • FedRAMP Ready, which is not the same as authorised
  • Gartner Magic Quadrant Leader, 2025
  • 99.6% fraudulent-document detection rate

Every item here is Incode's, verifiable at their trust centre. We are the credential layer on top of their verification engine, and we will send you their documentation rather than paraphrase it.

Fuzzy's own posture

ARCHITECTURE, NOT CERTIFICATES

  • The verification pipeline creates and stores no face template, face-geometry scan or biometric embedding
  • Append-only audit records, chained with a keyed hash
  • Per-organisation API credentials, scoped and revocable
  • Signed webhooks, with rotating secrets
  • Enumeration and sweep detection per credential
  • AES256 server-side encryption at rest, and encryption in transit
  • United States data residency

Fuzzy does not itself hold SOC 2 or ISO 27001 today. We would rather tell you that plainly than let you assume otherwise and find out during diligence. Ask us where that work stands and we will give you a real answer and a date.

Architecture and controls

Six controls your reviewer will care about.

AUDIT INTEGRITY

An insider cannot rewrite history.

Audit records are append-only and chained with an HMAC under a key held outside the database. Someone with full write access but no key cannot alter a record and relink the chain. Keys rotate without invalidating older records, and each record carries the key id that signed it.

TENANCY

Your data is scoped to your key.

Every API credential belongs to one organisation, carries explicit scopes, and can be revoked independently. Reads are constrained to that organisation. A credential record itself carries no organisation reference at all, because the credential belongs to the person, not to you.

ABUSE PREVENTION

Harvesting looks different from working.

Rate limiting counts distinct people queried per hour rather than total calls. Re-checking the same person is normal behaviour. Querying hundreds of different people quickly is a sweep, and that is the pattern we watch for and throttle.

DISCLOSURE

The holder decides what is shared.

A presentation carries only the claims the holder scoped, fixed at the moment it is minted. It is redeemable exactly once, it expires, and the token is stored only as a hash, so possession of the original is the credential.

INFRASTRUCTURE

AWS, United States regions, with stated retention.

Hosted on AWS in US regions, primarily us-east-1. Relational data in managed RDS, secrets in AWS Secrets Manager, static delivery via CloudFront. No data residency outside the United States. Verification result data is kept only as an allowlisted projection; the verification pipeline never stores a verbatim vendor payload. The verified profile and badge photo last the life of the account. ID document numbers, street addresses and postal codes were purged in August 2026 and are no longer collected. Ask us for the current retention schedule in writing rather than taking a number off a web page.

INTEGRATION FOOTPRINT

One endpoint. No new systems.

Server to server over one authenticated API, with request ids on every call and idempotency keys so a retry cannot double-charge or double-record. No hardware, no agent, nothing installed on your network.

Paperwork

Where each document actually stands.

Including the two that are not done. You will find out anyway, so you may as well find out from us.

IN PLACE

FERPA, via a data processing agreement.

Handled contractually through a DPA. Send us your institution's template and your counsel's redlines rather than asking us to send ours first.

IN PROGRESS

VPAT and Section 508.

Conformance work is running on a parallel track alongside deployment. That is the arrangement Barry University accepted. We will tell you exactly where it stands rather than claim it is finished.

NOT YET COMPLETED

HECVAT.

We have not been through one yet. If your institution requires it, send it over and we will complete it properly rather than pretend it is already on file.

Six things we will not claim.

  • We are not FedRAMP certified, and neither is Incode. Incode is FedRAMP Ready, which means the documentation exists. Full authorisation requires a sponsoring federal agency and is a separate step. Anyone telling you otherwise is guessing.
  • Incode's certifications are not ours. We will never list SOC 2 or ISO 27001 without saying whose they are.
  • A verified badge does not mean a person is safe. It means they are real and unique. We will not market it as a safety guarantee, on campus or anywhere else.
  • We do store one face photo, and we say so. It is the selfie from your verification, and it is the badge photo. We are not going to claim we hold no face data when a person’s face is the point of the product.
  • A failed check is not proof of fraud. What we hand you is a category and never a reason, so we cannot and will not tell you an applicant was fraudulent. That judgement stays with your own review process. We will not claim more than that: the vendor's own diagnostic text exists in our internal result records, it is never returned on any partner or public surface, and it is never a fraud finding.
  • Nobody is blocked for non-completion. Anyone who cannot verify gets an in-person or video path through your office. We will put that in the contract.

Ask us anything

Send the questionnaire. You will get answers, not adjectives.

schools@fuzzyverify.com

Send your security questionnaire, your HECVAT, your DPA template, or just the three questions your CISO actually cares about. A person answers, in writing, with dates rather than reassurances.

If something in our posture is a genuine blocker for your institution, we would rather establish that in week one than in month four.