Security & data protection
GSE is designed like a bank — verified, authorized, auditable.
Sworn self-attestation + qualified electronic signature
No passport, ID card or driving licence is ever uploaded or stored. Your identity is legally established through a sworn self-attestation under penalty of perjury and a qualified electronic signature under eIDAS Art. 25 and the U.S. ESIGN Act, with timestamp, IP address and device user-agent captured in an immutable audit record.
Minimal data retention
GSE stores only verification status, provider reference ID, timestamp, country and result. Raw identity documents are not retained by GSE.
Encryption & access controls
Sensitive fields are encrypted at rest. Access is restricted and every access is logged for audit.
Secure authentication
Password hashing, session controls, and role-based access. Admin actions are recorded in immutable audit logs.
GDPR-aligned
Explicit consent, purpose limitation, right of access, portability and deletion. A Data Processing Agreement is available on request.
Signed authorization
Every request GSE sends is backed by your signed authorization — version, timestamp, IP address and signed authorization reference are stored with the signature.
