Security and trust
The hard questions, answered plainly.
If your procurement, legal or technology team has a question this page does not answer, ask it. We would rather answer a hard question before a contract than discover it afterwards.
How do you know someone is a real person?
Three checks, in sequence, before anyone participates.
- A genuine document. The person presents a government-issued identity document, and the document itself is checked to be real, not a photograph of a photograph and not a forgery.
- A live human being. The person is checked to be physically present and alive at that moment. Not a photograph, not a recording, not a mask, not a generated image.
- The face matches. The live person is matched against the photograph on the document they presented.
Only when all three pass can that person take part.
How do you stop somebody participating twice?
This is the question that matters most, and the one most systems answer badly.
Blocking a repeated email address or phone number stops nothing. A determined person has many of both.
Verdika checks the person, not the credential. When somebody attempts to take part a second time, the system recognises them against everyone who has already taken part in that exercise. That holds even if they present a different name, a different document, a different email address and a different phone number.
One person participates once. The credential they use is irrelevant.
Is the vote secret?
Yes. Participation and choice are held separately.
The record shows that a verified person took part. It does not show what they chose. The result shows what was chosen. It does not show who chose it.
Both facts are provable. Neither can be joined to expose an individual's vote.
Who controls the data?
You do. The institution running the exercise is the data controller. We host and process on your instruction, under a written agreement.
Your register remains yours. Your results remain yours. We do not sell, share, rent or reuse your data, and we do not use it to build anything else.
What is actually stored, and for how long?
Only what the exercise requires, and only for as long as it is required.
Identity checks establish that a person is real and unique. The system retains the proof that verification happened and its outcome, not a copy of the person's identity documents beyond what the verification process itself requires.
Retention periods are set in your agreement, not by us unilaterally. When the period ends, the data is deleted.
Under attack
What happens if the system is attacked?
A fair question, and any organisation that has lived through a disputed result is right to ask it.
Access is tightly held
Every component has only the permissions it needs for its own job. There is no general-purpose credential that opens everything.
Every action is recorded
Administrative actions are written to a record designed so it cannot be quietly altered. An attempt to interfere leaves evidence.
Not one key for everything
The verification record and the result are separately protected, so compromising one does not produce a usable, undetectable change to the other.
Continuously examined
Verdika is tested adversarially before changes are released, and watched in live operation by our own engineering assurance practice.
If anything is detected, you are told in writing, with what happened and what it affected.
What about people without smartphones or good networks?
- No app is required. Verdika runs in an ordinary phone browser.
- It is built for modest devices and imperfect connections. Someone who loses connection does not lose their place or their submission.
- Assisted participation is supported. A supervised desk lets an official help, while the identity verification still happens on the participant, so assistance never becomes substitution.
Where is the data held?
On managed cloud infrastructure, with encryption in transit and at rest. The hosting region is confirmed in your agreement, and we will accommodate a specific jurisdictional requirement where your regulator or your law requires one.
Can we have our own deployment?
Yes. Institutions with strict requirements are given a dedicated deployment of Verdika, separate from every other client, with its own data and its own access.
This is the standard arrangement for government and regulated buyers, and it is included in enterprise scoping.
Who is accountable?
Verdika is built and operated by AlphaIT Engineering. Alpha Innovation Technologies - F.Z.C is licensed by the Free Zones Authority of Ajman, United Arab Emirates, licence 33549. Alpha Innovation Technologies Ltd is registered with the Corporate Affairs Commission, Nigeria, RC 7450573.
A named engineering contact is assigned to every deployment, and written commitments on availability, incident response and support are set out in your agreement.
Bring us your hardest question
We will put you in front of the engineers who built it, not a sales team reading from a sheet.