Trust Infrastructure

Trust = decision + receipt + auditability.
This page documents our infrastructure commitments. Artifacts included.

What we mean by trust

Trust is measurable. It's a permissioned decision under uncertainty - with proof.

1
Decision

Yes / Conditional / No. Clear, actionable, enforceable.

2
Receipt

Proof of what was decided, when, and why. Tamper-evident.

3
Auditability

Searchable, versioned, transparent. For you and your auditors.

Receipts & Audit Trails

Every decision emits a receipt. Every receipt is searchable, exportable, and auditable.

Receipt Contents
Receipt ID Unique identifier (e.g., rcpt_7f3k9x2m)
Decision Yes / Conditional / No
Confidence Tier Low / Medium / High
Reason Category Non-sensitive explanation
Timestamp UTC, ISO 8601 format
Flow ID Which flow triggered this decision
Policy ID + Version Which policy was applied
Signals Used Categories only (not raw PII)
Override Log If human intervention occurred
Audit Hash Tamper-evident integrity check
Search by: Flow ID, Policy ID, Receipt ID, Time Range, Decision Type

Policy Engine

Policies are versioned, testable, and rollback-ready. No surprises.

Versioning

Every policy change creates a new version. Full history preserved. Receipts reference exact version used.

Rollback

One-click rollback to any previous version. New bad policy? Undo in seconds.

Change Logs

Who changed what, when, and why. Auditors love this.

Sandbox Mode

Test policy changes against real traffic without affecting production decisions.

Data Handling

We minimize data by default. Retention is configurable. You control what stays.

Data Retention Matrix
Data Type Default Retention Configurable?
Decision receipts 90 days Yes
Signal categories 90 days Yes
Raw input data Not stored N/A
Policy versions Indefinite Limited
Override logs 1 year Yes
Data minimization
We don't store what we don't need
Redaction support
Sensitive fields can be redacted
Access controls
Role-based access to data

Human Review & Overrides

Conditional decisions route to your review queue. Overrides are logged and produce their own receipts.

Conditional Routing
  • Conditional decisions enter review queue
  • Configurable escalation rules
  • SLA tracking on review time
Override Requirements
  • Reason required (dropdown + notes)
  • Override produces its own receipt
  • Full audit trail preserved
Note: Override receipts include: who overrode, when, reason category, and resulting decision.

Abuse Controls

Controls to prevent abuse and protect system integrity.

Rate Limiting

Configurable per-flow, per-user, and global limits. Prevent enumeration attacks.

Repeated Actor Controls

Detect and flag repeat offenders across sessions and identities.

Monitoring & Alerting

Real-time monitoring. Configurable alerts for unusual patterns.

Bot Detection

Identify automated attempts to bypass verification.

AI Governance

How our models work, what they don't do, and how you control them.

What the model does
  • Classification of document types and authenticity signals
  • Anomaly detection for unusual patterns
  • Risk scoring based on configurable thresholds
  • Signal aggregation into decision categories
What it doesn't do
  • No raw PII exposed in receipts
  • No biometric claims unless explicitly enabled
  • No autonomous decisions without policy constraints
  • No training on your data without consent
Evaluation & Monitoring All systems nominal
Metric Description Threshold Current Last checked
false_positive_rate Legitimate requests incorrectly flagged < 2% 0.8% Continuous
false_negative_rate Risk events missed by the model < 1% 0.3% Continuous
model_drift_score Performance degradation over time < 0.05 0.02 2026-01-20
latency_p99 Decision response time < 500ms 247ms Real-time
override_rate Human overrides of model decisions < 5% 1.2% 2026-01-21
Threshold controls
Set confidence thresholds for Yes/Conditional/No
Human-in-the-loop
Conditional routes to review; overrides logged
Fallback behavior
You control hold/allow when model is unavailable
Limitations: No model is perfect. We provide confidence tiers, not certainty. Conditional exists specifically to handle uncertainty with human judgment.

Reliability & Incidents

Trust means telling you when things aren't perfect.

Status Page

Real-time system status. Last 90 days uptime. Incident history.

View Status
Incident Process
  1. Detection + status page update
  2. Initial investigation
  3. Mitigation + communication
  4. Resolution + post-mortem
When we're down
  • Graceful fallback: You configure default allow/deny behavior
  • Kill switch: You can bypass Werify entirely if needed
  • Latency expectations: Decisions typically return in <100ms

Compliance Posture

We only list controls we have now. Roadmap items are labeled clearly.

Available Now
  • Data encryption at rest + in transit
  • Role-based access controls
  • Audit logging
  • Data retention controls
  • SOC 2 Type II In Progress
Planned
  • ISO 27001 certification
  • GDPR data processing addendum
  • HIPAA BAA (healthcare customers)
  • PCI DSS compliance
Need specific compliance documentation? Contact our security team.

Artifacts Library

Downloadable artifacts for your security review and integration.

Download the Trust Pack

Forwardable to security and procurement - no call required.

Browse Trust Pack
Sample receipts (4) Retention matrix Architecture diagram Failure modes
Updated: 2026-01-22 • Version: v1.0
Sample Receipts

4 receipt types (Identity, Documents, Access, Transactions)

Identity Docs Access Txns
Architecture Diagram

System architecture and data flow

Download PDF
Data Retention Matrix

Full retention policy details

Download JSON
Policy Templates

Starter templates for common use cases

Browse Templates
Failure Mode Behavior

What happens when we're down

Download PDF
Security Whitepaper

Detailed security controls overview

Download PDF

Questions about our trust infrastructure?

Our security team is happy to walk you through the details.

Graceful fallbacks · Kill-switch · Configurable retention · View status