ISO 27001 Certified

Security built for regulated industries

Mesh ID protects your client data with multi-layered encryption, EU-only data residency, and an immutable blockchain audit trail. Every architectural decision is made for compliance-first environments.

Mesh ID is ISO 27001 certified. Our information security management system is independently audited and certified to the international standard.

Three pillars of data protection

Every layer of the Mesh ID architecture is designed to keep your data protected, private, and auditable.

Secured Communications

All traffic is encrypted via HTTPS using Extended Validation (EV) certificates. Certificates use SHA256RSA with 2048-bit keys, issued by Sectigo. Each component operates in an isolated container environment, limiting the blast radius of any incident.

  • Certificate-based private/public key pairs
  • EV certificates, SHA256RSA, 2048-bit keys
  • Issued and verified by Sectigo
  • Full container isolation per component

Bank-Grade Encryption

Mesh ID combines RSA 2048-bit asymmetric encryption with AES256CBC symmetric encryption. RSA secures the key exchange. AES256CBC secures the data. This combination is the same standard used across the global banking and financial services industry.

  • RSA 2048-bit for key encryption
  • AES256CBC for data encryption
  • Data encrypted in transit and at rest
  • No unencrypted data paths

Multi-Key Multi-Layered

Every individual field in your data is encrypted with its own unique, randomly generated AES256 key. That key is then encrypted using the recipient's RSA 2048-bit public key. There is no single point of compromise. A breach of one key exposes one field only. Mesh ID itself has zero visibility into the data stored in your environment.

  • Unique AES256 key per data field
  • Field-level key encrypted with recipient's RSA public key
  • No single-key exposure risk
  • Zero data visibility to Mesh ID
EU Data Residency

Your data stays in the EU. Full stop.

Mesh ID is hosted exclusively on AWS in Dublin, Ireland. Your data never leaves the European Union. There are five or more layers of separation between the public internet and your stored data.

Private cloud infrastructure
Dedicated private and public networking, not shared multi-tenant infrastructure.
Internal and external firewalls
Layered firewall controls at the perimeter and within the internal network boundary.
Encrypted storage at rest
All stored data is encrypted. There is no readable data layer accessible without decryption keys.
Cloud Provider AWS
Data Centre Region Dublin, Ireland
Data Jurisdiction European Union (GDPR)
Security Layers 5+
Data Transfer Outside EU Never
Blockchain Audit Trail

Your audit trail is locked in time

Every action taken in Mesh ID is written to an immutable, blockchain-backed event log. Compliance records cannot be altered, backdated, or deleted after the fact. When a regulator or inspector reviews your files, they see the complete, unmodified history of every decision.

  • Tamper-proof: no record can be altered after creation
  • Every decision is documented and timestamped at the point it is made
  • Inspection-ready for MONEYVAL, FATF, or internal audit at any moment
  • Provides a definitive, defensible record for regulatory proceedings
Why this matters
Compliance records that cannot be questioned

In regulated industries, the integrity of compliance records is not a detail. Regulators and inspectors can and do challenge whether records were altered after the fact. A blockchain-backed audit trail removes that question entirely.

No other onboarding platform in this space can make that claim with the same technical foundation.

How we handle PII

We apply a data minimisation approach. Your clients' personal data is processed only for as long as it needs to be.

Identity verification via Jumio

Mesh ID partners with Jumio for identity document verification. Jumio is PCI compliant and operates from an EU data centre. All verification data is processed and held by Jumio only for the duration of the verification check.

Immediate PII deletion

Once a verification outcome is confirmed, all personally identifiable information is immediately deleted from Jumio's servers. This deletion is double-confirmed before the verification is marked complete in Mesh ID. Your client's PII does not persist beyond what is strictly necessary.

Trust Center

Our full security posture, in one place

Certifications, sub-processors, privacy policies, and security documentation. Everything your InfoSec team needs to complete vendor due diligence.

Visit Trust Center ↗
Security Factsheet

Download the Security Factsheet

The full technical overview of Mesh ID's security architecture. Written for IT and InfoSec teams conducting vendor due diligence.

Talk to our security team

Have specific security requirements or need to complete a vendor security questionnaire? We're ready to help.

Get in touch
📄
Free download
The Mesh ID Reg Pack
Everything you need to perform your internal risk assessment, notify your regulator if required, and complete vendor due diligence on Mesh ID.
Download now

Press Esc to close