ASSURANCE & COMPLIANCE

Security is the product.

Border systems hold the most sensitive data a state processes. Misha Systems is engineered, certified and audited for that reality — and every assurance claim on this page is verifiable under NDA.

STANDARDS & CERTIFICATIONS

ISO 27001INFORMATION SECURITY MANAGEMENT

Security management across engineering, operations and support, with documented risk treatment and continuous improvement.

WCAG 2.2 AAACCESSIBILITY

Officer-facing and public-facing interfaces are built to accessibility requirements for public-sector services.

GDPR-alignedDATA PROTECTION

Personal data is processed under the deploying authority's jurisdiction, with defined retention, minimisation and audit trails.

EU interoperabilityREGULATION-READY

Interfaces designed for alignment with EU travel-document and border-systems interoperability requirements.

SOVEREIGN ARCHITECTURE

The platform is designed to run entirely under the deploying authority's control — on-premises, in sovereign cloud, or as a hybrid. Sovereignty is an architectural property, not a hosting checkbox.

A-01

No external data path

All processing, storage and biometric matching run inside the deploying authority's infrastructure. Nothing leaves the perimeter by default.

A-02

Air-gapped operation

Deployment models support fully disconnected operation, with controlled, logged update channels when connectivity exists.

A-03

State-owned data

The agency owns every record, template and log. Contractual exit terms guarantee full export in open formats.

A-04

Replayable audit

Every automated decision is deterministic and logged with full input context — any clearance can be replayed and defended years later.

ASSURANCE EVIDENCE

01

Security dossier

Architecture, data-flow and threat-model documentation, shared under NDA with your security team before any technical disclosure.

02

Penetration testing

Independent testing ahead of each major release cycle; summaries and findings triage made available to agency reviewers.

03

Audit evidence

Exportable event logs and decision records formatted for oversight bodies and internal audit teams.

NDA-GATED BRIEFINGS
The full security dossier is available to agencies under NDA.

Request a briefing and our security team will walk your reviewers through architecture, controls and evidence.