Skip to main content

How Konfir Protects Data Security & Privacy

Security and privacy principles are baked into our product and process.

Jacob avatar
Written by Jacob
Updated over 6 months ago

Konfir is built to meet high standards of data protection and security, ensuring transparency and trust for both organisations and applicants.

All data is processed and protected in accordance with our Organisation Terms, Data Processing Appendix, and Privacy Notice.


Security by Design

Konfir replaces outdated reference checks - often done over email - with a secure, consent-based verification process that gives applicants full control over their data.

To protect personal information, we implement multiple layers of security:

Security Layer

How it's applied

Encryption

All data is encrypted at rest and in transit using modern, industry-standard protocols

Access Controls

Strict role-based permissions limit who can access personal data

Data Minimisation

Only the minimum necessary data is collected to complete a verification

Audit & Monitoring

We conduct continuous monitoring, audit logging, and security testing

Hosting

Entirely hosted on AWS using enterprise-grade infrastructure

Privacy by Design

Privacy is embedded throughout Konfir’s product and operational practices, ensuring that personal data is handled responsibly and in line with data protection law from the outset.

Principle

How it's applied

Consent-Driven

All data sharing is opt-in by design - nothing is accessed or disclosed without applicant permission

Restricted Access Requests

Konfir’s access to the data sources applicants consent to connect are one-time, read-only access requests that are immediately and automatically revoked by the data source provider once data is connected

Data Minimisation

Only the minimum data required to fulfil a verification is processed

Transparency

Clear, upfront information is provided through our Privacy Notice and during the verification process

Konfir’s design approach ensures compliance with the principles of Data Protection by Design and by Default, as outlined in the UK GDPR and supported by our Organisation Terms.

Our Certifications

  • ISO 27001:2013 certified

  • UKDIATF (UK Digital Identity & Attributes Trust Framework)

  • UK GDPR and other applicable data protection laws

Built-In Compliance

Konfir manages all technical and compliance elements, including:

  • Consent capture and logging

  • Data handling, storage, and retention

  • Secure third-party subprocessor management

This means your organisation doesn’t need to manage additional certifications or infrastructure - and remains fully GDPR compliant when using Konfir.

See our Trust Portal andSub-Processor List for more detail.

Did this answer your question?