Security & data protection

GSE is designed like a bank — verified, authorized, auditable.

Sworn self-attestation + qualified electronic signature

No passport, ID card or driving licence is ever uploaded or stored. Your identity is legally established through a sworn self-attestation under penalty of perjury and a qualified electronic signature under eIDAS Art. 25 and the U.S. ESIGN Act, with timestamp, IP address and device user-agent captured in an immutable audit record.

Minimal data retention

GSE stores only verification status, provider reference ID, timestamp, country and result. Raw identity documents are not retained by GSE.

Encryption & access controls

Sensitive fields are encrypted at rest. Access is restricted and every access is logged for audit.

Secure authentication

Password hashing, session controls, and role-based access. Admin actions are recorded in immutable audit logs.

GDPR-aligned

Explicit consent, purpose limitation, right of access, portability and deletion. A Data Processing Agreement is available on request.

Signed authorization

Every request GSE sends is backed by your signed authorization — version, timestamp, IP address and signed authorization reference are stored with the signature.

Start my self-exclusion