Skip to content
TRUST CENTER

Trust, earned — and documented.

How we keep your users' identity data safe, where it lives, and the documents that back it up. We tell you plainly what's in place today and what's on the way.

COMPLIANCE & CERTIFICATIONS

Compliance and certifications

GDPRIn place

DPA & data-subject request tooling

EU data residencyIn place

Your EU region, your choice

DORA-readyOn roadmap

Financial-sector controls — planned

SOC 2 Type IIOn roadmap

Planned — audit not yet scheduled

ISO 27001On roadmap

Planned for 2026

EUDI WalletOn roadmap

Tracking the 2026 rollout

We don't claim certifications we don't hold. Items marked “In progress” or “On roadmap” are exactly that — ask us for the current status and we'll show you where things stand.

SECURITY CONTROLS

EU-only infrastructure

All compute and storage in EU regions; personal data and audit logs stay in your EU region.

Encryption everywhere

TLS in transit, encryption at rest, secrets isolated per environment.

GDPR program

DPA, subprocessor list, erasure and export — first-class.

Tamper-evident audit

Hash-chained logs of every sign-in and change, exportable.

Least privilege

Scoped access, reviewed regularly, logged end to end.

Responsible disclosure

A clear path to report issues, and we act on them.

SOVEREIGNTY, IN RECEIPTS

No third parties on our pages

Zero third-party fonts, analytics, CDNs or trackers. Open the network tab: your visit never touches a US server.

Every outbound call, inventoried

We keep a jurisdiction verdict for every network call the service makes — sovereignty is audited, not assumed.

Self-hosted bot defense

Our CAPTCHA is a self-hosted proof-of-work: no third-party challenge, no data sent to any captcha vendor.

Tenant-bound tokens

Access tokens are cryptographically audience-bound to your tenant — a token minted for one tenant is invalid against another.

Tamper-evident audit

Sign-ins and changes are hash-chained and externally anchored, so tampering is detectable.

Leave whenever you want

Export your users — including real password hashes — so you can migrate off without forcing everyone to reset. No lock-in by design.

Every item here is live today and verifiable — inspect our pages, decode a token, or ask us to walk you through it.

OUR COMMITMENTS TO YOUR DATA

Data residency you control

You choose Frankfurt or Paris at setup. Personal data and audit logs stay in that EU region; we do not move them outside the EU/EEA in the ordinary course of running the service.

Data subject requests

Access, rectification, erasure, restriction and portability are built into the product and the API. We assist your DSRs and respond to our own within one month, as the GDPR requires.

Sub-processors, transparent

A current list of every sub-processor, all EU-located, with at least 30 days' notice before any change so you can object.

Breach notification

We notify you of any personal-data breach affecting your data without undue delay — and within 72 hours where feasible — with what we know and what we're doing.