Identity verification_
How Codility’s identity verification works, what it captures, where that data lives, and how long it is kept. Written for security and compliance reviewers evaluating Codility.
Summary
The short answer, before the detail below.
Codility’s identity verification runs on a dedicated verification partner’s platform. The partner captures the ID document image, performs the face match, and holds the identity fields. Codility receives the verification result only: a pass or fail status, with a reason when a candidate does not pass. No ID images, biometric templates, or identity field data are transmitted to or stored on Codility’s infrastructure.
What is captured
Two different parties hold two different sets of data. The table below separates what the verification partner captures from what Codility receives.
| Data element | Held by | Detail |
|---|---|---|
| ID document image | Partner | An image of the candidate’s ID document, captured during verification. |
| Face match | Partner | A biometric match of the candidate’s face against the ID document photo. |
| Identity fields | Partner | Standard ID fields: name, date of birth, document number, expiration date, and country of issue. |
| Verification result | Codility | A pass or fail status. When a candidate does not pass, a description of why is included. |
Codility does not receive or store the ID image, the biometric face match, or the identity field data at any point in this flow.
How verification works
Three steps, all driven by the candidate, with the same data flow every time.
-
Notified
The candidate is introduced to the verification step in the default invitation email and on a dedicated intro page before the assessment. The page lists what the candidate needs, the available verification options, and links to the verification partner’s terms of service.
-
Verified
The candidate completes verification on the partner’s platform, using one of three paths: a QR code or a text-message link to verify on mobile, or a link to verify inside the desktop assessment environment. Verification is automated by default. The face match and document check are performed by the partner’s system, not by a live proctor.
-
Result returned
Codility receives the verification result. The ID image, the face match, and the identity fields remain on the verification partner’s infrastructure and are not passed to Codility.
Sub-processor model
The identity verification partner operates as a sub-processor under a standard sub-processor agreement. Codility does not operate the verification step directly. The partner runs the document check and face match, and Codility receives only the result.
Where data is processed and stored
Processing location and storage location, by data element.
- ID image, face match, identity fields
- Processed and stored on the identity verification partner’s infrastructure. Not transmitted to Codility at any point.
- Verification result
- Stored on Codility’s infrastructure as a pass or fail status, with a reason recorded on failure.
The source material reviewed for this document does not name the verification partner or specify the partner’s data hosting region. If your review requires a named sub-processor and its processing region, request the current sub-processor list from your Codility account team.
How long data is retained
Default retention at the verification partner, and how it can be changed.
| Stage | Window | What happens |
|---|---|---|
| Review | 90 days | Data is available for review at the verification partner. |
| Archive | 3 years | Data moves to archive at the verification partner following the review window. |
| Deletion | After archive | Data is permanently deleted following the archive period. |
Retention is customizable. The verification partner can be instructed to align retention with your organization’s data policy, including shorter review and archive windows, through the standard sub-processor agreement.
The 90-day review and 3-year archive figures are carried forward from Codility’s April 2026 product one-pager on identity verification. This reference does not have a more recent source to re-verify those figures against. Confirm current retention defaults with your Codility account team before citing them in a signed security questionnaire response.
Who data is shared with
Parties in the identity verification flow.
- Identity verification partner
- Sub-processor. Captures the ID image, performs the face match, and holds identity fields. Operates independently of Codility’s infrastructure.
- Codility
- Receives the verification result only. Does not receive or store ID images, biometric templates, or identity field data.
No other party receives identity verification data as part of this flow.
Compliance credentials
Credentials that apply to Codility as a platform. Identity verification data itself is governed primarily by the verification partner’s sub-processor agreement.
- SOC 2 Audited.
- ISO 27001 Certified.
- GDPR Compliant. A Data Protection Impact Assessment is available on request.
- CCPA Compliant.
Requesting more detail
What a reviewer can ask for beyond this document.
- Data Protection Impact Assessment Available on request through your Codility account team.
- Sub-processor list Request the current list, including the named identity verification partner and its processing region.
- Custom retention terms Ask your account team to align verification partner retention with your organization’s data policy.
- Security questionnaire responses Your Codility account team can provide a completed standard questionnaire or respond to a custom one.