At a glance
Audits & certifications
SOC 2 Type 2
Controls proven in operation. An independent audit under the AICPA Trust Services Criteria confirmed that Didit’s security, availability, and confidentiality controls operated effectively over the March–July 2026 observation period — not just that they exist on paper. Issued July 30, 2026. Report available under NDA.
SOC 2 Type 1
Control design verified. The point-in-time audit of the design of Didit’s security, availability, and confidentiality controls that preceded the Type 2 observation period. Issued April 9, 2026.
ISO/IEC 27001:2022
Certified information-security management. Didit’s Information Security Management System covers the verification platform end to end — design, development, and operation. Valid through June 3, 2027; certificate excerpts available on request.
ISO/IEC 27017 & 27018
Cloud security and cloud privacy. Extended cloud-specific controls (27017) and dedicated protections for personally identifiable information in cloud environments (27018) that build on the ISO 27001 certification.
iBeta Level 1 — ISO/IEC 30107-3
Biometric anti-spoofing, lab-tested. A NIST-accredited laboratory ran 360 presentation attacks across six attack categories against Didit’s liveness detection — printed photos, screen replays, masks, and more. Zero got through.
FSM Jugendschutz geprüft
German youth-protection certification. Germany’s youth-protection self-regulator (FSM) certified that Didit’s Age Verification System reliably establishes a closed user group under Section 4(2) JMStV — so only verified adults reach age-restricted content. Certified June 29, 2026.
Spanish regulator attestation
Safer than in-person, per financial regulators. After a year-long supervised test (November 2024 – July 2025), Spain’s Tesoro Público, Banco de España, SEPBLAC, and CNMV concluded Didit’s NFC + liveness verification is at least as safe as in-person ID checks under anti-money-laundering rules — the only provider with this validation.
EBA / MiCA compatibility
Remote onboarding, regulator-grade. An independent legal opinion confirms Didit’s remote onboarding meets the EBA Remote Customer Onboarding Guidelines (EBA/GL/2022/15) and is compatible with the EU AML Single Rulebook and MiCA. Memo available on request.
GDPR
EU data protection, processor role. Didit operates as your data processor with Article 32 technical and organizational measures: AES-256 at rest, TLS 1.3 in transit, EU-default data residency, configurable retention, and erasure via API. DPA and TOMs available on request.
We add new certifications all the time. If your compliance team needs a specific certification, framework, or attestation that isn’t listed here, book a demo and tell us — we’ll walk you through our roadmap and what we can provide today.
Related resources
Security & Compliance
The full security posture: encryption, data protection, fraud signals, and the security FAQ.
Security & Compliance center
Download reports, certificates, and assessments from the public trust center.