> ## Documentation Index
> Fetch the complete documentation index at: https://docs.didit.me/llms.txt
> Use this file to discover all available pages before exploring further.

# Certifications & attestations

> Every certification, audit, and regulatory attestation Didit holds: SOC 2 Type 2, ISO 27001, iBeta Level 1, FSM youth protection, Spain's Tesoro/SEPBLAC validation, EBA/MiCA legal opinion, and GDPR.

Didit's security and compliance posture is verified by independent auditors, accredited laboratories, and financial regulators — not self-declared. This page lists every credential we hold today. Reports and certificates are available from the [Security & Compliance center](https://didit.me/security-compliance/), directly in this page's cards, or from your Didit representative.

## At a glance

| Credential                    | Framework / issuer                             | Status                                                    |
| ----------------------------- | ---------------------------------------------- | --------------------------------------------------------- |
| SOC 2 Type 2                  | AICPA Trust Services Criteria                  | Issued July 30, 2026 (March–July 2026 observation period) |
| SOC 2 Type 1                  | AICPA Trust Services Criteria                  | Issued April 9, 2026                                      |
| ISO/IEC 27001:2022            | Accredited certification body                  | Valid through June 3, 2027                                |
| ISO/IEC 27017 & 27018         | Cloud security & cloud privacy extensions      | Active                                                    |
| iBeta Level 1 PAD             | ISO/IEC 30107-3, NIST-accredited lab           | Passed — zero successful attacks                          |
| FSM Jugendschutz geprüft      | FSM (Germany), Section 4(2) JMStV              | Certified June 29, 2026                                   |
| Regulator attestation (Spain) | Tesoro Público, Banco de España, SEPBLAC, CNMV | Concluded July 2025                                       |
| EBA / MiCA compatibility      | Independent legal opinion                      | Current                                                   |
| GDPR (EU 2016/679)            | Data processor, Article 32 measures            | Compliant                                                 |

## Audits & certifications

<CardGroup cols={2}>
  <Card title="SOC 2 Type 2" icon="shield-halved">
    **Controls proven in operation.** An independent audit under the AICPA Trust Services Criteria confirmed that Didit's security, availability, and confidentiality controls **operated effectively over the March–July 2026 observation period** — not just that they exist on paper. Issued July 30, 2026. Report available under NDA.
  </Card>

  <Card title="SOC 2 Type 1" icon="shield">
    **Control design verified.** The point-in-time audit of the design of Didit's security, availability, and confidentiality controls that preceded the Type 2 observation period. Issued April 9, 2026.
  </Card>

  <Card title="ISO/IEC 27001:2022" icon="shield-check">
    **Certified information-security management.** Didit's Information Security Management System covers the verification platform end to end — design, development, and operation. Valid through June 3, 2027; certificate excerpts available on request.
  </Card>

  <Card title="ISO/IEC 27017 & 27018" icon="cloud">
    **Cloud security and cloud privacy.** Extended cloud-specific controls (27017) and dedicated protections for personally identifiable information in cloud environments (27018) that build on the ISO 27001 certification.
  </Card>

  <Card title="iBeta Level 1 — ISO/IEC 30107-3" icon="face-smile">
    **Biometric anti-spoofing, lab-tested.** A NIST-accredited laboratory ran 360 presentation attacks across six attack categories against Didit's liveness detection — printed photos, screen replays, masks, and more. **Zero got through.**
  </Card>

  <Card title="FSM Jugendschutz geprüft" icon="child-reaching">
    **German youth-protection certification.** Germany's youth-protection self-regulator (FSM) certified that Didit's Age Verification System reliably establishes a **closed user group under Section 4(2) JMStV** — so only verified adults reach age-restricted content. Certified June 29, 2026.
  </Card>

  <Card title="Spanish regulator attestation" icon="landmark">
    **Safer than in-person, per financial regulators.** After a year-long supervised test (November 2024 – July 2025), Spain's Tesoro Público, Banco de España, SEPBLAC, and CNMV concluded Didit's NFC + liveness verification is **at least as safe as in-person ID checks** under anti-money-laundering rules — the only provider with this validation.
  </Card>

  <Card title="EBA / MiCA compatibility" icon="scale-balanced">
    **Remote onboarding, regulator-grade.** An independent legal opinion confirms Didit's remote onboarding meets the EBA Remote Customer Onboarding Guidelines (EBA/GL/2022/15) and is compatible with the EU AML Single Rulebook and MiCA. Memo available on request.
  </Card>

  <Card title="GDPR" icon="lock">
    **EU data protection, processor role.** Didit operates as your data processor with Article 32 technical and organizational measures: AES-256 at rest, TLS 1.3 in transit, EU-default data residency, configurable retention, and erasure via API. DPA and TOMs available on request.
  </Card>
</CardGroup>

<Info>
  We add new certifications all the time. If your compliance team needs a specific certification, framework, or attestation that isn't listed here, [book a demo](https://didit.me/get-a-demo/) and tell us — we'll walk you through our roadmap and what we can provide today.
</Info>

## Related resources

<CardGroup cols={2}>
  <Card title="Security & Compliance" icon="shield-check" href="/getting-started/security-compliance">
    The full security posture: encryption, data protection, fraud signals, and the security FAQ.
  </Card>

  <Card title="Security & Compliance center" icon="globe" href="https://didit.me/security-compliance/">
    Download reports, certificates, and assessments from the public trust center.
  </Card>
</CardGroup>
