Document verification involves sensitive personal information. The product promise must begin by reducing what leaves, who accesses it, and how long it remains.
The customer determines which documents are verified and the compliance purpose. DIES Veredicto processes only what is necessary to execute that instruction.
A real operation may include documents, images, identifiers, dates, and derived evidence. The deployed dev accepts no real document or account.
Queries are scoped to the session tenant, internal identifiers remain opaque, and human decisions preserve adjudicator identity and time.
Local processing is the preferred destination. Any egress to an external provider requires an explicit gate, authorization, and applicable contractual terms.
Retention must follow contract and purpose. Active records, audit evidence, and cold retirement will have separate periods and verifiable operations.
The final version will establish channels for rights requests, security contacts, incident notice, and applicable jurisdiction.