Skip to main content

How do I know Konfir is safe?

Describes Konfir’s security measures, data handling practices, and certifications.

Hope Latham avatar
Written by Hope Latham
Updated over a week ago

Summary

Konfir is a UK Government-certified service built to the same security standards used by banks. You stay in control at every step: nothing is shared without your consent, access is one-time only, and Konfir never contacts your employers.


You stay in control

  • You choose which sources to connect (Banking, HMRC, Payroll).

  • Your login details are never seen or stored by Konfir.

  • Once your verification is complete, access closes automatically - no ongoing connection to your accounts.

  • Konfir only shares a verification output (e.g. confirmed employer, dates, income) with the organisation that requested it - never the raw data.


Your data is protected

  • UKDIATF certified (UK Digital Identity & Attributes Trust Framework).

  • Fully GDPR compliant and ISO 27001 certified.

  • Data is encrypted in transit and at rest (the same protection banks use).

  • Hosted on Amazon Web Services (AWS) with enterprise-grade security.


Your privacy is respected

  • Konfir never contacts or informs your current or past employers.

  • Only the organisation that requested your check (your verifier) will see the verification.

  • We apply data minimisation: we only collect what’s strictly needed for your verification, nothing else.


Independent oversight

Our systems and processes are regularly audited to maintain certification. This external oversight ensures we consistently meet industry-leading standards for privacy and security.

Did this answer your question?