Law Enforcement Guidelines
Effective date: March 30, 2026
Verifa is committed to protecting the privacy and security of our Customers and their applicants. We also recognize our obligation to comply with valid legal process. These guidelines describe the types of data Verifa may hold, the legal process required to obtain it, and the procedures for submitting requests.
1. Data Verifa May Hold
Depending on the Customer's configuration and applicable retention periods, Verifa may hold the following categories of data:
1.1 Customer Account Data
- Organization name and registration details
- Account administrator names and email addresses
- Billing information (payment method details are held by our payment processor, not by Verifa directly)
- API key metadata (creation date, last used, permissions)
1.2 Verification Session Metadata
- Session identifiers and timestamps (creation, completion, expiry)
- Verification status and result summary (passed, failed, needs review)
- Customer-provided reference identifiers
- IP address and device information of the applicant at the time of verification
1.3 Encrypted Biometric Data
- Face matching scores and derived biometric templates
- Retained per Customer configuration, typically for 90 days after session completion
- Encrypted at rest using AES-256-GCM encryption
1.4 Applicant Personally Identifiable Information (PII)
- Names, dates of birth, and addresses extracted from identity documents
- Document numbers and issuing country
- Encrypted at rest and retained per Customer configuration
2. Data Verifa Does NOT Hold
- Full document images: original identity document images and selfie photos are retained for the Customer-configured retention period (default 90 days), then permanently deleted
- Plaintext biometric templates: biometric data is encrypted at rest and is not stored in plaintext form at any time
- Applicant account credentials: Verifa does not create accounts for applicants; they interact with the Service through their Customer's integration
3. Legal Process Requirements
Verifa requires valid legal process before disclosing any data. The specific requirements depend on the jurisdiction and type of request.
3.1 United States Requests
For requests originating from U.S. law enforcement agencies:
- Subpoena: a valid grand jury subpoena or administrative subpoena is required for basic subscriber information and session metadata
- Court order: a court order issued under 18 U.S.C. 2703(d) or equivalent is required for detailed session records and transactional data
- Search warrant: a search warrant issued by a court of competent jurisdiction based on probable cause is required for content data, including applicant PII and biometric data
3.2 International Requests
Requests from law enforcement agencies outside the United States must be submitted through one of the following channels:
- A Mutual Legal Assistance Treaty (MLAT) request processed through the U.S. Department of Justice
- A request under an applicable executive agreement pursuant to the CLOUD Act
- Other recognized international legal cooperation mechanisms
Verifa generally cannot respond to direct requests from foreign law enforcement agencies that are not processed through an established legal cooperation channel.
3.3 Emergency Requests
In cases involving an immediate threat to life or serious physical injury, Verifa may voluntarily disclose data without standard legal process. Emergency requests must:
- Come from a verified law enforcement agency
- Clearly describe the nature of the emergency and the imminent threat
- Specify the data requested and how it relates to the emergency
- Be submitted by an authorized official of the requesting agency
Emergency disclosures are reviewed and approved by Verifa's legal team. Verifa reserves the right to decline emergency requests that do not meet these criteria.
4. Customer Notification
When Verifa receives a valid legal request for data related to a Customer's verification sessions, Verifa will notify the affected Customer before disclosing data, unless:
- Notification is prohibited by law, court order, or other binding legal restriction
- Verifa believes in good faith that notification would create a risk of injury, death, or destruction of evidence
- The request relates to an emergency disclosure under Section 3.3
When a non-disclosure obligation expires, Verifa will promptly notify the affected Customer.
5. Data Preservation Requests
Law enforcement agencies may request that Verifa preserve relevant data pending the issuance of formal legal process. Preservation requests are subject to the following:
- Verifa will preserve identified data for 90 days upon receipt of a valid preservation request
- Preservation may be renewed for an additional 90-day period upon written request
- Preserved data will only be disclosed upon receipt of valid legal process as described in Section 3
- Preservation requests must identify the specific data to be preserved with reasonable particularity
6. How to Submit Requests
All law enforcement requests should be submitted to:
Verifa — Legal / Law Enforcement
Email: legal@withverifa.com
Each request must include the following information:
- The requesting agency's name and jurisdiction
- The name, badge number (if applicable), and contact information of the requesting officer
- A description of the legal authority for the request (statute, case number, warrant number)
- The specific data or records requested
- Any applicable time period for the data requested
- Identifying information for the relevant accounts or sessions (e.g., session IDs, email addresses, organization names)
Requests that do not include sufficient identifying information may be returned for clarification, which may delay the response.
7. Right to Challenge
Verifa reserves the right to challenge legal requests that we believe are overbroad, vague, or otherwise improper. This includes requests that:
- Seek data that is not relevant to the stated investigation
- Are overly broad in scope or time period
- Lack proper legal authorization
- Raise concerns about civil liberties, free expression, or privacy rights
When Verifa challenges a request, we will work with the requesting agency to narrow the scope to what is legally required and reasonably necessary.
8. Transparency
Verifa is committed to transparency regarding law enforcement requests. To that end:
- Verifa may publish aggregate statistics on the number and type of law enforcement requests received, to the extent permitted by law
- Statistics, if published, will not include information that could identify specific investigations, Customers, or applicants
- Verifa will not voluntarily provide law enforcement with bulk or real-time access to Customer or applicant data
9. Contact Us
For questions about these guidelines or Verifa's law enforcement response process:
Verifa — Legal
Email: legal@withverifa.com