Trust CenterUpdated August 2026
Trust, made inspectable.
See how Candour combines certified assurance, independent face-matching evaluation and standards-compliant controls to protect remote identity verification against modern fraud.
Verified assurance
Independent evidence. Compliant controls.
Two current certifications and one independent NIST evaluation provide distinct evidence across organisational security, end-to-end face verification and biometric matching.
Information security management
Candour operates an ISO/IEC 27001:2022-certified Information Security Management System for biometric person identity verification services and supporting functions.
- Risk and asset management
- Access control and secure development
- Supplier, incident and continuity management
- Ongoing surveillance and improvement
FIDO® Identity Verification · Face Verification
FIDO IDV Type 1
Level 1 v4.0
Candour-Biometrics v1.4.0 was independently evaluated by TÜV Informationstechnik GmbH. FIDO’s scenario-based programme exercises the complete selfie-to-document face verification flow through at least 10,000 tests.
- Deepfakes & spoof mediaPrint, screen, replay, mask and synthetic-face attack species
- Passive liveness / PADEvidence that the user is genuine and present in real time
- Demographic performanceBias analysis across skin tone, age and gender
- Biometric matchingSelfie-to-ID accuracy measured through FAR and FRR
- Injection resistanceCapture-bypass attempts using prior or synthetic image and video data
- FAR
- 0.00%
- FRR
- 4.40%
- IAPAR
- 1.76%
Results apply to the certified test setting. Certificate IDV100020241213001 · valid through 24 January 2028.
NIST FRTE 1:1 · formerly FRVT
Face matching tested at scale.
Candour’s candour-004 face recognition algorithm was evaluated by the US National Institute of Standards and Technology under its ongoing one-to-one verification protocol. The Visa–Border scenario is particularly relevant to remote identity verification because it compares document-style portraits with border-capture images.
Failure to Enrol (FTE) across all four reported datasets · candour-004 · NIST report dated 31 July 2026.
Trust at every layer
Protection follows the identity journey.
No single control carries the whole system. Candour combines capture safeguards, verification signals, data controls and operational governance.
-
01
Provenance
Capture provenance
Session binding, freshness checks, payload integrity, secure transport and anti-replay controls preserve the link between the device capture and the backend decision.
-
02
Binding
Certified identity evidence
Document checks, ICAO-compliant NFC/eMRTD validation, NIST-evaluated 1:1 face matching and FIDO-certified passive liveness/PAD can be combined for the required evidence route.
-
03
Resilience
Modern-attack resistance
Deepfake and presentation-attack detection are reinforced by CEN/TS 18099-aligned controls for injected video, virtual cameras, emulators, runtime integrity, sensor coherence and replayed genuine media.
-
04
Governance
Operational assurance
The certified ISMS provides the governance foundation for access, risk, suppliers, incidents, continuity, monitoring and continuous improvement.
Standards & regulation map
The framework—and our position.
This map shows where Candour is certified, externally evaluated, compliant or aligned. The stated position applies to the named controls and service scope.
| Framework | Why it matters | Candour position |
|---|---|---|
| ETSI EN 319 401 | A principal eIDAS trust-services standard covering policy, security, service operation and trustworthy electronic transactions. | Compliance alignmentCandour aligns its service policies and architecture with ETSI EN 319 401 through secure data protocols, encryption in transit and at rest, risk and access controls, auditability, business continuity and interoperable integration patterns for eIDAS 2.0 ecosystems. |
| ETSI TS 119 461 | Policy and security requirements for identity proofing used as a trust-service component. | Conformity alignmentThe identity-proofing flow implements requirements for evidence collection, biometric binding, liveness, attack resistance, secure processing, traceability and auditable decisions to support compliant trust-service deployments. |
| CEN/TS 18099:2024 | Evaluation of biometric data injection attacks that bypass or manipulate the capture channel. | Conformity implementationCandour implements live and release-stage IAMDM/IAIDM controls aligned to its requirements: secure messaging, capture provenance, app and device integrity, virtual-camera and emulator detection, passive liveness, deepfake detection, motion analysis and multi-sensor coherence. |
| ICAO Doc 9303 | Machine-readable travel documents, NFC chip data and document PKI. | Compliant capabilityNFC/eMRTD reading, data-group integrity and PKI validation implement applicable ICAO Doc 9303 structures and validation requirements. |
| ISO/IEC 19795 & 30107 | Biometric performance measurement and presentation attack detection testing and reporting. | Certified evidenceThe FIDO IDV Type 1 Level 1 v4.0 evaluation applies the relevant performance and mobile PAD profiles to matching, bona fide use and presentation-attack resistance. |
| eIDAS 2.0 | European digital identity, EUDI Wallets and trust-service requirements. | Compliance-readyCandour provides compliant building blocks for high-assurance evidence routes, EUDI Wallet onboarding and interoperable trust-service integrations, with deployment evidence mapped to the complete scheme. |
| GDPR & UK GDPR | Lawful, transparent and secure handling of identity and biometric data. | Compliant programmePrivacy-by-design, data minimisation, DPAs, restricted access, encryption, configurable retention and deletion controls support GDPR-compliant identity verification. |
| EU AI Act | AI governance, data quality, transparency, robustness and oversight. | Compliance programmeRisk management, performance and fairness monitoring, technical documentation, human oversight and security practices support compliant use in the applicable customer context. |
| NIS2 & Cyber Resilience Act | Risk governance, resilience and secure software lifecycle expectations. | Compliance readinessISO 27001-governed risk, vulnerability, incident, supplier, continuity and secure-development processes support NIS2- and CRA-compliant deployments. |
| ETSI EN 301 549 & WCAG 2.2 AA | Accessible digital services and user-facing verification flows. | Fully compliantCandour’s user-facing verification flow fully complies with WCAG 2.2 AA and applicable ETSI EN 301 549 requirements, including assistive-technology support, scalable text, AA contrast, reduced motion and passive liveness without flashing prompts. |
Compliance descriptions apply to the stated Candour controls and service scope. Certificates, external results, control mappings and deployment-specific evidence are available through the customer assurance process.
Data protection & deployment
Control the route your data takes.
In the standard EU SaaS configuration, processing takes place in EU/EEA data centres. Private-cloud, on-premises, hybrid and regional options can be agreed where data residency, sovereignty or certification requirements call for a different model.
Read our privacy policyverification
Purpose & minimisation
Data collection and processing are limited to the agreed verification purpose and customer configuration.
Protection
Sensitive data is protected in transit and at rest, with access restricted through least-privilege controls.
Retention
Retention is configurable by data category and customer requirement, subject to applicable legal obligations.
Accountability
DPAs, sub-processor information, data-flow material and customer-specific processing plans are available.
Questions worth asking
Trust should survive scrutiny.
These answers define the boundaries behind the headline claims. For a customer-specific assessment, ask us for the applicable evidence set.
Which claims are independently verified?
ISO/IEC 27001:2022 and FIDO IDV Type 1 Level 1 v4.0 are current certifications. NIST FRTE 1:1 is an independent government evaluation of Candour’s face-matching algorithm. The standards map identifies compliant controls, conformity implementation and alignment within each stated scope.
Can Candour support high-assurance identity proofing?
Candour combines ICAO-compliant NFC/eMRTD validation, biometric binding, certified passive liveness/PAD, capture-channel defences and auditable decisions to support high-assurance evidence routes. The evidence package maps these controls to the policy, integration and conformity scope of each deployment.
What protects against deepfakes and injection attacks?
FIDO-certified testing covers deepfakes, liveness, biometric matching, bias and injection resistance. Candour complements content analysis with CEN/TS 18099-aligned capture-channel controls, including secure messaging, session freshness, app and device integrity, virtual-camera and emulator detection, micro-motion analysis and multi-sensor coherence across live and release-stage capabilities.
What assurance material can customers review?
Depending on scope and confidentiality, Candour can provide certificates, supporting evaluation material, architecture and data-flow documentation, DPA and sub-processor information, control mappings, accessibility material and security policies. Sensitive evidence may require an NDA.
How does Candour approach biometric fairness?
The FIDO evaluation includes demographic testing and bias analysis across skin tone, age and gender. Candour reinforces this independent evidence with ongoing performance and fairness monitoring at the relevant operating thresholds.
Who is responsible for regulatory compliance?
Candour documents service responsibilities in the DPA and deployment scope. We provide GDPR-compliant controls, security and data-flow evidence, standards mappings and customer-specific processing documentation for the complete assurance review.
Assurance is contextual
Match the evidence to your risk.
Tell us your market, evidence route, deployment model and assurance target. We will provide the applicable certificates, NIST results, compliance mappings and implementation evidence.