For a service marketplace platform like debel.app—which connects freelancers, tutors, coaches, and contractors with clients and processes secure payments—compliance is crucial for building user trust and preventing fraud.

Didit can cover several core areas of compliance and identity security for debel.app:

1. KYC (Know Your Customer) & Identity Verification

To protect both clients and service providers on the marketplace, Didit verifies that users are who they say they are:

  • Document Verification: Instantly checks government IDs, passports, and driver's licenses across 220+ countries and 14,000+ document types.
  • Biometric Liveness & Face Match: Prevents bad actors from using printed photos, screens, or deepfakes to bypass checks. It matches the user's live selfie to their ID document in under two seconds.
  • Age Estimation: Ensures that service providers meet the legal age requirements to sign contracts or offer specific specialized services.

 

The comprehensive list of required KYC form fields for debel.app is categorized below by onboarding stage.

  1. Initial Account Mapping (The Toggle)

Before showing fields, ask the user to select their account type. This dynamically alters the downstream document requirements.

  • Account Type Selection (Radio Buttons: Individual / Freelancer OR Company / Corporate Agency)
  1. Tier 1: Core Identity Profile (Text Fields)

These fields capture basic personal declarations. The text entered here must match the submitted official documents exactly to pass automated anti-money laundering (AML) and sanction screen checks.

For Individuals & Company Representatives

  • First & Last Legal Name (Text)
  • Date of Birth (Date Picker — must enforce age restriction, e.g.,  years old)
  • Nationality (Dropdown)
  • Gender (Dropdown / Optional depending on regional framework)
  • Mobile Phone Number (Text input with mandatory country code prefix + SMS OTP validation)
  • Residential / Billing Address:
    • Street Address Line 1 & 2 (Text)
    • City (Text)
    • State/Province (Dropdown/Text)
    • Postal Code / ZIP (Numeric/Alphanumeric text)
    • Country (Dropdown)
  1. Tier 2: Document Verification (File Upload / Camera Integration)

Instead of standard file attachments that are highly vulnerable to fraud, this section should utilize an e-KYC SDK integration (like Veriff, Sumsub, or Jumio) to access the user’s camera.

Document Metadata

  • ID Document Type (Dropdown: National Identity Card (e.g., MyKad), Passport, Driver's License)
  • Document Identification Number (Alphanumeric text string)
  • Document Expiry Date (Date Picker)

Document Imagery

  • Front Cover / Front Side Photo (Image capture/upload)
  • Back Side Photo (Image capture/upload — mandatory for National IDs or Driver's Licenses)

Biometric Verification

  • Live Selfie or Liveness Video Check (SDK instruction directing user to blink/move head to ensure they are physically present and match the ID photo)
  1. Tier 3: Corporate Verification (Conditional Fields)

Show these fields only if the user selected Company / Corporate Agency in Step 1. Marketplace escrow platforms require this to trace Ultimate Beneficial Owners (UBOs) and prevent corporate tax evasion or laundering.

  • Legal Entity / Company Name (Text)
  • Trade Name / Operating Name (Text — if different from legal name)
  • Business Registration Number (Alphanumeric text — e.g., SSM number in Malaysia)
  • Tax Identification Number (TIN / SST / VAT) (Alphanumeric text)
  • Registered Business Address (Structured address fields)
  • Corporate Document Uploads:
    • Certificate of Incorporation / Business Profile (PDF or high-res image)
    • Proof of Operating Address (Utility bill or bank statement under the company name, less than 3 months old)
  • Ultimate Beneficial Owner (UBO) Declaration:
    • Name, DOB, and ID details for any individual holding greater than 25% voting rights or shares in the company.
  1. Tier 4: Financial Payout Setup (Escrow & Settlement Link)

Because debel.app manages secure milestone-based escrow payouts, the name on the destination bank account must match the verified KYC name to protect against third-party payout fraud.

  • Bank Country Location (Dropdown — determines routing fields)
  • Bank Name (Dropdown list of supported banks)
  • Bank Swift / BIC Code or Routing Transit Number (Alphanumeric text)
  • Account Holder Name (Read-only text, auto-filled from the verified legal/company name in Step 2/4)
  • Bank Account Number / IBAN (Alphanumeric text)
  • Proof of Account ownership (Optional Check) (File upload of a voided check or bank statement header showing name and account number clearly, with transactional data blurred out)
  1. Regulatory Risk Disclosures & Declarations

A final checkbox section ensuring absolute legal protection before submitting data to the compliance team.

  • PEP Declaration Toggle: "I confirm that I am not, nor am I related to, a Politically Exposed Person (PEP)."
  • Terms & Privacy Consent Checkbox: "I agree to the processing of my biometric and personal data for verification purposes under the Privacy Policy."

 

2. KYB (Know Your Business)

For contractors, coaching academies, or agencies registering on debel.app as corporate entities rather than individual freelancers:

  • Corporate Verification: Automates the process of verifying business registration, corporate structures, and active statuses across global registries.
  • UBO (Ultimate Beneficial Owner) Screening: Identifies and verifies the actual individuals behind a registered business entity to prevent shell company fraud.

3. AML (Anti-Money Laundering) & Transaction Monitoring

Because debel.app handles secure escrow payments, multi-currency support, and payouts:

  • Sanctions & PEP Screening: Regularly screens users against 10,000+ global watchlists, Politically Exposed Persons (PEPs) lists, and adverse media databases to block illicit funds.
  • Ongoing Monitoring: Keeps a continuous pulse on user risk profiles post-onboarding, triggering alerts if a verified freelancer or client lands on a regulatory blocklist later on.
  • Crypto/Wallet Screening: If debel.app decides to incorporate web3 or crypto payments, Didit offers direct screening of wallet addresses for high-risk flags.

4. Data Privacy & Sovereign Compliance

Managing sensitive personal and biometric data carries massive legal responsibilities:

  • GDPR Compliance: Didit is designed from the ground up to be fully compliant with the EU’s General Data Protection Regulation (GDPR). It acts as a data processor, while debel.app remains the data controller.
  • Data Minimization: To limit debel.app's liability, Didit can process biometrics in memory and return simple, tamper-proof boolean pass/fail outcomes, meaning debel.app doesn't have to store raw, sensitive biometric files.

5. Industry Certifications (Enterprise Trust)

If debel.app pitches services to large corporate clients who require high security standards, Didit carries the certified infrastructure to satisfy their IT audits:

  • SOC 2 Type I & ISO/IEC 27001 (Information Security Management).
  • iBeta Level 1 (ISO 30107-3) certification for biometric presentation attack detection.
  • EU AI Act Ready data governance and bias-monitoring capabilities.

 

Beyond the core KYC, KYB, and AML solutions, Didit provides several advanced technical and compliance features that directly target the unique operational model of a global marketplace like debel.app:

1. Progressive Onboarding (Tiered Verification)

Instead of forcing users to pass a complex ID check just to browse or list a basic service, Didit supports Progressive KYC:

  • Tier 1 (Lite Onboarding): Service providers sign up with fast, low-friction checks like Email & Phone Verification (via OTP/WhatsApp) and Age Estimation (using a simple selfie, without demanding an ID card).
  • Tier 2 (Full Verification): Fully comprehensive verification—ID scanning, facial liveness, and AML screening—is triggered only when a milestone is reached. For debel.app, this could trigger when a freelancer hits a specific payout threshold, registers a physical event, or applies to offer high-risk services.

2. Geolocation, VPN & Device Fingerprinting

Marketplaces are highly vulnerable to "sybil attacks" (creating fake accounts to leave fraudulent reviews or inflate ratings). Didit counters this with built-in device intelligence:

  • IP and Geolocation Analysis: Detects if a service provider claiming to be in Malaysia is actually routing their traffic through a VPN, proxy, or Tor exit node.
  • Device Fingerprinting: Flags when multiple accounts are being operated from the same physical device, mitigating rating manipulation and duplicate profile exploits.

3. Proof of Address (PoA) Verification

Because debel.app supports localized financial operations—such as installment options (currently offered in Malaysia)—verifying a user's local tax residency or physical address is critical:

  • Didit uses automated AI-powered OCR to parse and validate utility bills, bank statements, and official government letters in seconds to confirm a user's address.

4. NFC-Level Security (Government-Grade Verification)

For high-assurance contracts or instances where trust must be absolute (e.g., certified tutors, certified engineers, or on-site contractors):

  • Didit can read the NFC (Near-Field Communication) cryptographic chips inside modern e-passports and e-IDs.
  • Regulatory bodies (such as Spain's financial authority) have officially validated Didit’s remote NFC + liveness verification as being just as secure as verifying an ID in-person.

5. Multi-Language and Localization Support

Since debel.app prioritizes multi-language and global service capabilities, Debel compliance tech needs to match that global scale:

  • Didit natively supports identity documents in over 48 languages and handles localization smoothly, ensuring that international service providers do not abandon the onboarding process due to a language barrier.

 

For a platform like debel.app operating in Malaysia, PDPA (Personal Data Protection Act 2010) compliance is a mandatory legal obligation. Didit is designed to integrate into Malaysian workflows specifically to handle these requirements, acting as a data processor while Debel platform remains the data controller.

Here is how Didit supports Debel PDPA compliance requirements:

1. Alignment with Data Protection Principles

Didit’s infrastructure is built to satisfy the seven core principles of the PDPA, which governs how you collect, process, and store personal data:

  • Security Principle: Didit employs end-to-end encryption (TLS 1.3 in transit, AES-256 at rest) and maintains ISO/IEC 27001 and SOC 2 Type I certifications to protect data from unauthorized access or misuse.
  • Retention Principle: Debel have full control over data residency and lifecycle. Debel can configure retention policies per application (from 1 month to 10 years) or use API-based "process-and-purge" patterns to delete data immediately after verification, ensuring you don't store personal information longer than necessary.
  • Access & Integrity: Didit provides complete, timestamped audit logs for every action, allowing Debel platform to easily fulfill "Data Subject Access Requests" (DSAR) if a user asks to see or correct their data.

2. Handling Sensitive Personal Data (Biometrics)

Under recent PDPA amendments, biometric data (like facial scans for liveness checks) is classified as sensitive personal data.

  • Data Minimization: Didit allows you to minimize Debel legal risk by not forcing you to store raw, sensitive biometric files on Debel own servers.
  • Compliance Infrastructure: Didit’s biometric systems are iBeta Level 1 (ISO 30107-3) certified, meeting the rigorous standards required for handling such high-sensitivity identity data.

3. Localization and Cross-Border Transfers

PDPA has specific requirements for cross-border data transfers.

  • In-Country Processing: While Didit defaults to EU-based infrastructure (AWS), enterprise customers can enable in-country data residency options, keeping verification data within Malaysia to simplify Debel regulatory posture.
  • Processor Guarantee: As Debel data processor, Didit processes data only on Debel instructions and provides sufficient contractual guarantees regarding data protection, which is a required step for "outsourcing" Debel verification processes under PDPA.

4. Breach Notification Readiness

The 2024 PDPA amendments introduced mandatory data breach notifications (to the Commissioner and affected users).

  • Audit Trails: Didit provides the granular, exportable audit trails and security monitoring necessary to help you identify the scope of any potential incident, which is critical for meeting the mandatory 72-hour notification window.

Â