Security & Compliance

Enterprise-grade security, built in from day one

Zero-trust architecture, AES-256 encryption, NDPR compliance, immutable audit trails, and complete consent management — all included.

Security & Compliance

Enterprise-grade security, built in from day one

Security isn't an afterthought at EpiiXa. It's the foundation. Every layer of the platform is designed with zero-trust principles.

End-to-End Encryption

All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Encryption keys are managed via HSMs and rotated automatically.

TLS 1.3 in transit
AES-256 at rest
HSM key management
Automatic key rotation

Consent Tracking

Every verification is gated by explicit, recorded user consent. Full audit trails of what data was collected, when, and for whom.

Explicit consent capture
Granular permissions
Consent withdrawal support
NDPR aligned

Immutable Audit Logs

Every action — every API call, data access, decision, and change — is written to an append-only, tamper-proof audit log.

Append-only log architecture
Cryptographic integrity
90-day retention minimum
Exportable on request

Role-Based Access Control

Fine-grained RBAC lets you define exactly who on your team can access which data. Principle of least privilege enforced by default.

Custom role definitions
Attribute-based policies
Session management
SSO/SAML support

API Key Management

Scoped API keys with expiration, IP allowlisting, and per-endpoint permissions. Rotate keys without downtime.

Scoped API keys
IP allowlisting
Per-endpoint permissions
Zero-downtime rotation

Data Protection

Data residency controls, right-to-erasure support, and strict data minimization. We only store what's needed, for as long as needed.

Data residency controls
Right-to-erasure
Data minimization
Retention policies
Compliance Standards

EpiiXa is built to align with major data protection and financial compliance frameworks.

NDPR Compliant
GDPR Aligned
ISO 27001 Framework
SOC 2 Type II Aligned
PCI DSS Aware
AML/KYC Standards
FAQ

Frequently Asked Questions

Everything you need to know about EpiiXa. Can't find your answer? Talk to our team.

Proof of Address

Verification Process

Security

For Businesses

API & Integration

Africa's Identity Infrastructure

Building the Identity Infrastructure Africa Deserves.

Stop losing customers to failed KYC. Stop accepting unverifiable addresses. Start building on infrastructure that works for Africa.

Free to start
No credit card required
< 60 seconds
First verification
2 hours
API integration time
24/7
Support & uptime