Summary
Konfir is a government-certified service under the DIATF - built to the same security standards used by banks. You stay in control at every step: nothing is shared without your consent, access is one-time only, and Konfir never contacts your employers.
ℹ️ Note: Konfir is ISO 27001 certified, registered under the UK Government's Digital Identity & Attributes Trust Framework (DIATF), and operates in compliance with UK GDPR and the Data Protection Act 2018. These credentials are independently audited and verified.
You stay in control
You choose which data sources to connect (Banking, HMRC, Payroll, or Documents).
Your login details are never seen or stored by Konfir
Only a verified summary (employer, dates, income) is shared with your verifier -never your full data.
ℹ️ Note: When you connect a data source (like HMRC, your bank, or payroll), you sign in directly with that provider - not with Konfir. Konfir never sees or stores your credentials.
Access is read-only and temporary
All connections to your data are strictly limited:
Read-only - Konfir can retrieve data but cannot make changes, submit forms, or take action on your behalf
One-time access - connections automatically close once the required data is retrieved
💡 Tip: You can verify this in your provider account (e.g. your bank's authorised connections or HMRC "Manage Agents"), though no action is needed from you.
Your data is protected
🏛️Government Certified - Konfir is certified under the UK Digital Identity & Attributes Trust Framework (UKDIATF).
☁️ Bank-Grade Security - Konfir's services are hosted securely on Amazon Web Services (AWS) with enterprise-grade safeguards.
🔒End-to-end encryption - Data encrypted in transit and at rest — the same level of protection used by banks.
✅ GDPR compliant and ISO 27001 certified
Your privacy is respected
Konfir never contacts your employers or anyone else about your verification.
Only the organisation that requested your check (your verifier) sees the verified results.
We apply data minimisation - collecting only what’s needed for your verification, and nothing more
Independent oversight
Konfir’s systems and processes are regularly reviewed and audited by independent assessors to maintain certification and uphold industry-leading standards for privacy and security, including ISO 27001.
Need more help?
See: What data does Konfir collect and use?
See: Your data rights
Contact: [email protected]

