Security & compliance

How we handle candidate data

Verification touches people's identities during one of the more vulnerable moments of their lives. This page states plainly what we do, what we refuse to do, and where the legal responsibility sits.

What VeriAxis is

  • A technology service that confirms a candidate controls a mobile number and that the number is linked to the name they gave.
  • A coordinator that hands a candidate off to a licensed consumer reporting agency when an employer orders credit or background screening.
  • A service processor acting on the documented instructions of the employer who requested the check.

What VeriAxis is not

  • Not a consumer reporting agency. We do not assemble or issue consumer reports.
  • Not a decision-maker. We produce no score, ranking, or hiring recommendation about any candidate.
  • Not a data broker. We do not sell candidate data or build cross-employer profiles.

Consent comes first, every time

No check begins before the candidate has read what will happen and actively agreed to it.

Nothing is pre-ticked

Each consent is a separate, empty checkbox. Bundled or implied consent is not consent, and we do not accept it.

Two distinct permissions

One to verify the number against mobile carrier records. One to receive a single text message containing the verification link. A candidate can give the first and refuse the second.

The record is kept

We store the timestamp, the IP address, and the exact version of the language shown, so the consent can be evidenced later.

Read the exact consent language

Fair Credit Reporting Act

Where the line falls between our service and a consumer report.

Identity verification results are not consumer reports. They may not lawfully be used as the sole basis for denying employment, and our Terms of Service prohibit that use.

When an employer orders credit or background screening

The partner agency is the consumer reporting agency of record. That agency, not VeriAxis, is responsible for the accuracy of the report, for dispute handling, and for the consumer's rights under the FCRA. Through the partner's own compliant flow, the candidate receives:

  • A clear and conspicuous disclosure, in a standalone document, that a consumer report may be obtained for employment purposes.
  • A separate written authorization, which the candidate signs before anything is ordered.
  • A copy of the federal Summary of Your Rights Under the Fair Credit Reporting Act, and any state-required notices.

An employment credit report is not a credit score

This surprises most employers, so we state it plainly. A credit check run for employment purposes returns a pared-down report: open accounts, balances, payment history, collections, and public records. It does not include a FICO or VantageScore number, and no reputable agency will supply one for a hiring decision. Any vendor offering an employer a candidate's credit score for hiring should be treated with suspicion. Ordering an employment credit report also does not affect the candidate's own score.

Responsibilities that stay with the employer

As the end user of a consumer report, the employer must certify a permissible purpose, use the report only for that purpose, and follow the two-step adverse action process: a pre-adverse action notice with a copy of the report and the summary of rights, a reasonable waiting period, and then a final adverse action notice. VeriAxis surfaces these steps in the dashboard and provides the partner agency's templates, but the legal obligation is the employer's.

Credit history in hiring is restricted

An employer's right to consider credit history depends on where the candidate is and what the role involves.

Roughly a dozen states, along with several cities, limit or prohibit the use of credit history in employment decisions, generally with narrow exemptions for roles carrying genuine financial responsibility, fiduciary duty, or access to sensitive assets. States with such laws include California, Colorado, Connecticut, Hawaii, Illinois, Maryland, Nevada, Oregon, Vermont, and Washington. New York State's restriction took effect on 18 April 2026 and is among the broadest in the country. City-level rules exist in places including New York City, Chicago, and Philadelphia.

This page is not legal advice and the law keeps moving. Confirm the current rule for each candidate's jurisdiction and each role with your own counsel before ordering a credit check. Our dashboard raises a warning where a restriction is likely to apply, but the determination of permissible purpose is the employer's to make and to defend.

Getting credit screening switched on takes time

Credit bureaus require any business that orders employment credit reports to be credentialed first, which normally includes a third-party physical inspection of the premises where reports are ordered and reviewed, and typically takes two to three weeks. That applies to the employer, not only to us. We will tell you what is needed and coordinate with the partner agency, but nobody can switch this on the same day.

How we reduce the risk of misuse

  • Credit screening is off by default and is enabled per account, not per click.
  • The employer records the role and the reason before an order can be placed.
  • Orders route to the partner agency's compliant flow; we never pull credit data ourselves.
  • Accounts that misuse screening lose access under our Acceptable Use Policy.

Text messages

A candidate receives at most one transactional text message per verification request, and only after asking for it by ticking the SMS consent box. The message contains the verification link and nothing else. We never send marketing messages to a number collected for verification, we never share or sell these numbers for marketing, and any reply of STOP ends messaging to that number immediately. Standard message and data rates from the candidate's carrier may apply.

Data protection

Encryption

TLS 1.2 or better in transit, with HTTP Strict Transport Security. Encryption at rest for all stored records.

Retention

Verification records are deleted ninety days after a request closes. Shorter windows are available on request. Deletion is automated, not manual.

Data minimisation

We ask for a name and a mobile number. We do not collect Social Security numbers, dates of birth, photographs, or identity documents for identity verification.

Access control

Results are visible only to users in the requesting workspace. Roles limit who can order screening. Administrative access uses multi-factor authentication.

Audit logging

Who created, viewed, exported, or deleted a record, and when. Logs are retained separately from candidate personal data.

Incident response

Documented process for triage and containment, with notification to affected customers without undue delay and within applicable legal deadlines.

Subprocessors

Categories of third parties that may process candidate data on our behalf.

Category Purpose Data
Cloud hosting and network securityServing the application, storing records, blocking abuseAll service data
Phone identity networkConfirming number possession and name match against carrier recordsName, mobile number
Consumer reporting agenciesCredit and background screening ordered by an employerData the candidate provides directly to the agency
Transactional messagingDelivering verification links and result notificationsName, email address, mobile number
Payment processingInvoicing and collecting payment from employersEmployer billing data only, never candidate data

A current list of named subprocessors, our data processing addendum, and security documentation are available to customers and prospects on request at [email protected]. We give notice before adding a subprocessor that processes candidate personal data.

Candidate rights

Wherever they live, any candidate may ask us what we hold about them, ask for a correction, or ask for deletion. We respond within thirty days. Residents of California and other states with comprehensive privacy laws additionally have the rights described in our Privacy Policy, including the right not to be discriminated against for exercising them.

We do not sell personal information and we do not share it for cross-context behavioural advertising.

Write to [email protected] or use the form on our candidate page. Where an employer is the controller of the record, we forward the request to them and support them in answering it.

Reporting a vulnerability

Email [email protected] with steps to reproduce. We acknowledge within two business days. Please give us a reasonable window to fix an issue before disclosing it, and do not access data belonging to anyone but yourself while testing. We will not pursue legal action against good-faith research conducted under these terms.

Compliance contact

Questions about this page, our data practices, or a vendor security review:

VeriAxis Group LLC
926 Stevens Dr, Cheyenne, WY 82001
[email protected]

Last updated September 13, 2026.