Last updated: January 2026
This document provides a transparent overview of the security architecture, privacy controls, and global compliance posture of Aye and its products, including AyeFace, a biometric-enabled payment, wallet, and loyalty platform.
Security, privacy, and regulatory compliance are foundational principles in Aye’s product design, technical architecture, and operational governance.
Aye operates AyeFace as a technology platform that enables:
- Biometric-based user authentication (AyeFace)
- Wallet and loyalty orchestration
- Payment initiation through licensed financial institutions
- AI-driven personalization and fraud risk detection
Aye is not a bank and does not directly settle funds. Payment authorization and settlement are executed by licensed merchant acquirers and payment service providers in accordance with applicable financial regulations.
Aye aligns its data protection practices with major global privacy frameworks, including:
- EU General Data Protection Regulation (GDPR)
- Malaysia Personal Data Protection Act (PDPA)
- Singapore Personal Data Protection Act (PDPA)
These frameworks govern the collection, processing, storage, transfer, and deletion of personal and biometric data.
Across all systems, Aye applies:
- Explicit and informed consent, especially for biometric data
- Purpose limitation — data used only for stated functions
- Data minimisation
- Security by design and by default
- User rights enablement (access, correction, deletion where applicable)
Biometric data is treated as sensitive personal data.
- Raw facial images are not stored
- Facial data is converted into non-reversible mathematical templates
- Templates are encrypted and access-controlled
- Processing occurs only after explicit user opt-in
Biometric data is never sold, reused, or shared outside its stated purpose.
Aye uses AI to support authentication, fraud detection, and personalization.
- Human oversight for critical decision paths
- Continuous monitoring for performance, drift, and anomalies
- Audit logging for AI-driven actions
- Monitoring for bias and false-acceptance rates in biometric systems
Aye’s AI governance is designed to be compatible with emerging global AI regulations, emphasizing:
- Transparency and traceability
- Explainability where applicable
- Accountability and risk-based controls
- Payments are executed through licensed banks and acquirers
- Aye acts as a technology orchestration layer
- Aye does not store card numbers or bank credentials
Aye supports ecosystem-level risk management through:
- Identity verification workflows
- Transaction anomaly detection
- Fraud pattern analysis
- Alignment with FATF AML/CFT best practices
Final AML/KYC responsibility remains with licensed financial institutions.
Aye operates primarily on Google Cloud Platform (GCP) using enterprise-grade security controls, including:
- Zero-trust network principles
- Network segmentation
- Encryption at rest and in transit
- Identity and Access Management (IAM)
- Secure CI/CD pipelines
Aye uses Google Cloud Security Command Center (SCC) as a centralized security management and posture monitoring platform to:
- Detect infrastructure misconfigurations
- Identify vulnerabilities and threats
- Maintain continuous compliance visibility
- Provide real-time security findings and alerts
Security Command Center enables proactive risk detection, prioritization, and remediation across cloud assets.
Aye applies industry-recognized cryptographic standards, including:
- AES-256 for data at rest
- TLS 1.2 / TLS 1.3 for data in transit
- Public-key cryptography (ECC / RSA) for authentication and signing
- Secure hashing (e.g. SHA-256 or stronger) for integrity verification
- Managed Key Management Services (KMS) and hardware-backed protection where available
Cryptographic keys are never hardcoded in application logic.
Blockchain is used selectively as a security and integrity layer, not as a payment rail.
Primary objectives include:
- Tamper-evident audit trails
- Non-repudiation of critical events
- Cross-party trust without exposing sensitive data
On-chain (hashed or encrypted references only):
- Consent proofs
- Authentication or transaction event hashes
- System integrity checkpoints
- Configuration or model version fingerprints
Never stored on-chain:
- Biometric images or templates
- Personal Identifiable Information (PII)
- Payment credentials
- Monetary transaction values
All sensitive data remains off-chain, encrypted, and access-controlled.
Blockchain enables verification that:
- Biometric templates have not been altered
- User consent existed at the time of use
- Authentication events are tamper-evident
This enhances auditability without decentralizing personal data.
Smart contracts, where used, are limited to:
- Event verification
- Timestamping
- Integrity validation
They do not:
- Authorize payments
- Transfer funds
- Replace regulated financial institutions
Aye integrates Tencent liveness detection technology to mitigate biometric spoofing attacks, including:
- Printed photos
- Screen replays
- Video injections
- Mask-based impersonation
Tencent’s liveness detection provides multi-dimensional facial analysis and real-time verification, significantly reducing false acceptance rates in physical and digital environments.
Aye aligns its internal controls with internationally recognized standards, including:
- ISO/IEC 27001 — Information Security Management
- ISO/IEC 27701 — Privacy Information Management
- ISO/IEC JTC 1/SC 37 — Biometrics standards
- Secure Software Development Lifecycle (SSDLC) practices
Formal certifications may be pursued as the organization scales.
Aye maintains documented incident response procedures covering:
- Detection and containment
- Impact assessment
- Regulatory and stakeholder notification where required
- Root cause analysis and remediation
Security events are monitored continuously across infrastructure and application layers.
Users and merchants are entitled to:
- Transparency on data usage
- Access and correction of personal data
- Consent withdrawal where legally applicable
- Secure deletion aligned with regulatory requirements
Requests can be submitted through Aye’s official support channels.
Aye maintains ongoing compliance through:
- Internal risk and security reviews
- Third-party security assessments
- Regulatory horizon scanning
- Employee training on privacy and security
Security and compliance are treated as continuous processes, not one-time certifications.
For security or compliance inquiries, please contact via email privacy@aye-ai.org or reach out to us on Telegram https://t.me/paywithayeface
