Certifications
Certifications

ISO/IEC 27566-1:2025 Age Assurance Certification
ISO/IEC 27566-1:2025 Age Assurance Certification
Gataca is certified against ISO/IEC 27566-1:2025, the international standard for online age assurance.
The certification validates our privacy-first approach to age verification, combining digital identity wallets, facial age estimation and passkey-based re-verification under a single trusted framework.
Certified by ACCS, the assessment covers security, privacy, accuracy, fairness, accessibility and governance controls designed to protect users while helping platforms comply with age-restricted access requirements.
Vouch allows platforms to verify whether a user meets a required age threshold without receiving personal information, creating a safer and more privacy-preserving experience for both businesses and users.

ISO/IEC 27001:2022 Certification
ISO/IEC 27001:2022 Certification
Gataca is ISO/IEC 27001:2022 certified.
ISO 27001 is the globally recognized standard for Information Security Management Systems (ISMS).
This certification confirms our commitment to implementing best practices and continuously improving our risk-based security program. Our management system was inspected by Prescient Security LLC, an accredited certification body for information security management systems.
ISO 27001 requires organizations to certify their information security management controls across their entire IT infrastructure, from asset management and access control to human resource security and application security.

Recognized by KJM for Age Assurance in Germany
Recognized by KJM for Age Assurance in Germany
Germany maintains one of the most demanding regulatory frameworks for online age assurance worldwide. The German Commission for the Protection of Minors in the Media (KJM) evaluates systems designed to prevent minors from accessing age-restricted content and services.
Amie Vouch incorporates privacy-preserving age assurance mechanisms that can support organizations operating in regulated environments and seeking alignment with German age protection requirements.

Positive Privacy Assessment with the Spanish Data Protection Authority
Positive Privacy Assessment with the Spanish Data Protection Authority
Privacy and data minimization are core principles of Amie Vouch.
A comprehensive Data Protection Impact Assessment (DPIA) was conducted and submitted to the Spanish Data Protection Agency (AEPD), evaluating the privacy implications of the solution and the safeguards implemented to protect users.
The assessment supports Amie Vouch’s privacy-by-design approach and reinforces our commitment to responsible age assurance.

Registered with the UK Information Commissioner’s Office (ICO)
Registered with the UK Information Commissioner’s Office (ICO)
The Information Commissioner’s Office (ICO) is the United Kingdom’s independent authority responsible for upholding information rights and data protection laws.
Gataca maintains an active ICO registration, demonstrating its commitment to transparency and compliance with UK privacy requirements when operating age assurance services.

Designed to Support Digital Services Act (DSA) Requirements
Designed to Support Digital Services Act (DSA) Requirements
The European Digital Services Act introduces enhanced obligations for online platforms regarding the protection of minors and the mitigation of risks associated with age-restricted services.
Amie Vouch provides privacy-preserving age assurance capabilities that help organizations implement effective age checks while minimizing the collection of personal data.

GDPR Compliant by Design
GDPR Compliant by Design
The General Data Protection Regulation (GDPR) establishes strict requirements for the processing of personal data within the European Union.
Amie Vouch minimizes the amount of information disclosed during age verification processes and supports privacy-preserving approaches such as reusable credentials, selective disclosure and attribute verification.
This enables organizations to verify age without collecting more personal information than necessary.