When your ID scan is the target: how to assess vendor security

Phil Aitken, Global Chief Information Security Officer, GBG

Reports have confirmed a widespread data breach involving drivers' license and identity documents, allegedly including infrared and ultraviolet scans utilized for authenticating physical IDs. This incident is the latest in a series across our sector this year, serving as a valid reminder for organizations that depend on document verification to reassess their vendor selection and auditing processes. 

Security isn't a feature bolt-on — it's architectural 

Document verification providers hold some of the most sensitive data that exists: government IDs, biometric scans, personal identifiers that can't be reissued the way a password can. That's a different category of responsibility compared to most SaaS businesses, and it should be treated that way from the beginning, not patched on later.  

Privacy, regulatory and security requirements are built into how we operate. We maintain governance, oversight and appropriate external certifications because we recognize the duty of care we have to our customers and their customers. You can learn more about our policies, processes, standards and certifications in our Trust Centre. Most vendor conversations centre on match rates, speed and fraud detection accuracy. Fewer focus on what happens to the document after it has been checked, although that is often where the real risk lies. 

Why this category of breach is different 

Whilst passwords can be changed the information lost if an identity is breached can have life long consequences for people. A compromised driver's license, especially one that includes the security layers designed to prove it's genuine, is much harder to remediate. A driver's license carries more than a photo: infrared and ultraviolet layers, chip data, and other embedded features exist specifically to defeat forgery. When those layers are exposed, the very features meant to defeat fraud become tools for it.  

Does the data need to persist at all? 

One of the main principles we've upheld over the years is that document persistence should be a choice, not a default. Our platform can process and verify an identity document without retaining it — verify, then delete. If a customer has a legitimate business need to retain data, for a better user experience, for example, that's available on their terms as well. 

The tradeoff is real. Retained data can be useful for interface continuity, model improvement, and audit trails. We think the right answer is to give organizations that choice explicitly, rather than making retention an invisible platform default.    

Five questions worth asking any verification vendor 

If this news has prompted your own security, privacy or fraud teams to take a closer look at your identity verification stack, here’s what we would focus on:  

  1. Retention, not just accuracy. Can documents be verified without being stored, and is that a real option or just marketing? If data is kept, how is it done, where is it stored, for how long, and who makes that decision? 

  2. What's actually protected, not just the visible image. What happens to the sensitive authentication layers such as IR (Infrared), UV (Ultraviolet) and chip data, specifically, beyond just the front and back scans? 

  3. Encryption, in transit and at rest. This should be a baseline, not a differentiator but it's worth confirming rather than assuming.

  4. Certifications and what they actually cover. ISO 27001 or SOC 2 serve as initial references for due diligence but do not replace it. Inquire about the scope, the date of the last audit, and whether it encompasses the particular product and data flow you plan to use.  

  5. Track record and incident response. Every vendor in this space is a target; the question is how prepared they are. What's their incident response SLA, who gets notified and when, and how long have they operated without a material lapse in trust?

Trusted document authentication and identity verification for 20+ years.  

With over twenty years supporting highly regulated organizations worldwide, we have developed document authentication capabilities designed to verify government-issued IDs, detect fraudulent or tampered documents and strengthen confidence in identity verification processes. While this expertise does not eliminate all risks, it helps ensure our approach is built to withstand rigorous scrutiny. 

If you have any questions about your document verification setup, data management or retention policies, reach out to us anytime 

Phil Aitken is Global Chief Information Security Officer, GBG