Security & data protection
Built to be trusted with your brand
An anti-counterfeiting platform is only as strong as its keys. Here is how we protect yours, what we collect when a product is scanned, and how to get the detail your security team needs.
Codes that cannot be forged
- Every code is cryptographically signed with a secret key unique to your organisation, so a code we did not issue fails verification outright.
- Signature checks are written to resist timing analysis.
- You can rotate your organisation's key at any time, without reprinting codes that are already on products.
- Cloned and copied labels are detected from scan behaviour, not just from the code itself.
Encrypted in transit and at rest
- All traffic to VerifyGuard is served over HTTPS.
- Your organisation's signing key is encrypted before it is stored, using strong industry-standard encryption.
- Credentials and encryption keys are held in a dedicated managed secret store, never in application code or configuration files.
- Passwords are hashed with bcrypt and per-user salts. API keys and distributor codes are stored only as irreversible hashes and shown to you once, at creation.
Access control and accountability
- Role-based access with Owner, Admin and Viewer roles.
- API keys are scoped to specific permissions and can be revoked instantly.
- Sensitive actions — key rotation, API key and distributor changes, bulk downloads and administrative changes — are written to an audit log.
- Rate limiting and abuse protection are applied across the platform.
Where your data lives
- Your data is hosted inside the European Union, with an established enterprise cloud provider, which keeps EU customers on familiar ground for GDPR purposes.
- We do not publish a detailed map of our infrastructure. Architecture details, sub-processor lists and completed security questionnaires are shared with customers and prospects under NDA.
What a scan collects
- Approximate location (city and country) derived from the scanner's IP address.
- A device description (for example phone model, operating system and browser) and a first-party identifier, used to detect one code being scanned on many devices.
- No account, name or phone number is required from a consumer to verify a product.
- The Developer API returns verdicts only. It never exposes device fingerprints or internal risk signals.
Third parties we rely on
The categories of service that process data on our behalf. The named list, with each provider's role and location, forms part of our data processing agreement and is available on request.
| Category | Purpose | Location |
|---|---|---|
| Cloud hosting & database | Runs the platform and stores your data | European Union |
| Payment processing | Card payments — we never see or store card numbers | Per provider |
| Email delivery | Account, alert and invoice emails | Per provider |
| IP geolocation | Approximate city/country for a scan | Per provider |
Security questionnaire or vulnerability report?
Email security@verifyguardafrica.com for vendor due diligence, our data processing agreement and sub-processor list, or to report a vulnerability responsibly. We answer questionnaires in detail under NDA.
Talk to our team