Every obligation, one platform
Sender ID registration, identity verification, indemnity declarations, agreements, compliance evidence, renewals and privacy rights — all audit-logged, all in one white-labelled hub.


Sender ID Registration
Manage sender ID registrations across your whole customer base from one register. VERA integrates directly with the ACMA Sender ID Register — submissions, brands and partner relationships — and keeps every registration current.
Sender ID format validation runs before submission. Expiry tracking triggers automated renewal reminders, and every sender ID carries a full history and rejection log. The architecture is registry-agnostic, built for new jurisdictions as regimes mature.

Identity Verification (KYC/KYB)
Identity verification built into customer onboarding, not bolted on afterwards. Business verification runs through an integrated verification provider, with outcomes recorded as compliance evidence.
MFA is enforced before registration actions — an unverified sender simply can't get registered. Verification status is tracked on every customer record.

Indemnity Declarations & Compliance Evidence
Structured indemnity declarations are captured, stored and audit-logged within the platform, giving operators and their customers a defensible record of compliance commitments.
Consent records, verification outcomes and compliance documents sit in a versioned evidence repository with watermarked viewing. Everything is retained for 7 years, with every significant action audit-logged — who, what, when.

Agreements
Know exactly which documents each customer has accepted, and when — terms of service, compliance declarations, contracts. Operators define what a customer is expected to accept; the customer accepts through their own portal.
Acceptance evidence is stored and downloadable, with dates recorded against every document. It rolls up into each customer's live compliance status alongside verification, declarations and sender ID state — the record of what else a customer has signed up to, sitting right next to their indemnity declarations.

Privacy Rights
A privacy rights (DSR) workspace handles the full lifecycle of a data subject request — deletion, access, rectification, portability, restriction — from submission through review, execution and completion. A PII location register maps where personal data actually lives, and changes to it automatically propagate into open requests, so nothing gets missed mid-flight.
Due dates are regulation-aware, with alerts as statutory deadlines approach. Requests chain across the supply relationship: an operator can pass a request down to customers and vice versa, with the sub-processor's assistance window sized so the upstream party still meets its own statutory clock (GDPR Art. 28(3)(e) style). Task tickets go to the teams holding the data, carrying the authority trail.
Each request closes with a completion certificate: identifiers in scope, locations assessed, actions completed with dates, and any residuals — evidence you can hand to a regulator or customer. Operators and customers get separate views, and every step is audit-logged.
The rest of the obligation surface
- Automated renewal tracking and real-time compliance status across every sender
- White-labelled platform you deploy as your own branded compliance hub
- Customer portals for verification, declarations, agreements and privacy requests
- Team management with role permissions and full audit history
- Multi-account structure for operators managing child customer accounts
- Integrations across the registration and verification workflow
Coming next
Spam complaint intake and resolution is coming to VERA. Ask us for current build status and delivery timing before scoping a program around it.
See the platform run against a real sender base.
Book a demo and we'll walk through registration, verification and evidence end to end.