Konfir is built to meet high standards of data protection and security, ensuring transparency and trust for both organisations and applicants.
All data is processed and protected in accordance with our Organisation Terms, Data Processing Appendix, and Privacy Notice.
Security by Design
Konfir replaces outdated reference checks - often done over email - with a secure, consent-based verification process that gives applicants full control over their data.
To protect personal information, we implement multiple layers of security:
Security Layer | How it's applied |
Encryption | All data is encrypted at rest and in transit using modern, industry-standard protocols |
Access Controls | Strict role-based permissions limit who can access personal data |
Data Minimisation | Only the minimum necessary data is collected to complete a verification |
Audit & Monitoring | We conduct continuous monitoring, audit logging, and security testing |
Hosting | Entirely hosted on AWS using enterprise-grade infrastructure |
Privacy by Design
Privacy is embedded throughout Konfir’s product and operational practices, ensuring that personal data is handled responsibly and in line with data protection law from the outset.
Principle | How it's applied |
Consent-Driven | All data sharing is opt-in by design - nothing is accessed or disclosed without applicant permission |
Restricted Access Requests | Konfir’s access to the data sources applicants consent to connect are one-time, read-only access requests that are immediately and automatically revoked by the data source provider once data is connected |
Data Minimisation | Only the minimum data required to fulfil a verification is processed |
Transparency | Clear, upfront information is provided through our Privacy Notice and during the verification process |
Konfir’s design approach ensures compliance with the principles of Data Protection by Design and by Default, as outlined in the UK GDPR and supported by our Organisation Terms.
Our Certifications
ISO 27001:2013 certified
UKDIATF (UK Digital Identity & Attributes Trust Framework)
UK GDPR and other applicable data protection laws
Built-In Compliance
Konfir manages all technical and compliance elements, including:
Consent capture and logging
Data handling, storage, and retention
Secure third-party subprocessor management
This means your organisation doesn’t need to manage additional certifications or infrastructure - and remains fully GDPR compliant when using Konfir.
See our Trust Portal andSub-Processor List for more detail.
