“Didit’s NFC + active liveness verification offers security equivalent to or greater than in-person verification.”
— Official report, Spanish Treasury (tesoro.es)
SOC 2 Type 2
Service Organization Controls — Type 2. An independent audit against the AICPA Trust Services Criteria confirmed Didit’s security, availability, and confidentiality controls operated effectively over the March 9 – July 1, 2026 observation period. Issued July 2026 (Type 1 issued April 2026). Report available to enterprise customers under NDA.
FSM Jugendschutz geprüft
German youth-protection certification. Germany’s youth-protection self-regulator (FSM) certified that Didit’s Age Verification System reliably establishes a closed user group under Section 4(2) JMStV, so only verified adults reach age-restricted content.
ISO/IEC 27001
Information security management. Didit maintains a certified Information Security Management System (ISMS) covering the design, development, and operation of the identity verification platform. Certificate excerpts available on request.
ISO/IEC 27017
Cloud security controls. Extended cloud-specific security controls that complement our ISO 27001 certification, ensuring robust protection for cloud-based verification services.
ISO/IEC 27018
Cloud privacy protection. Dedicated controls for protecting personally identifiable information (PII) in cloud environments, going beyond general data protection requirements.
GDPR Compliant
Full EU data protection compliance. Didit is fully compliant with the General Data Protection Regulation. We act as a data processor — you remain the data controller. DPA and TOMs available on request.
iBeta Level 1 — ISO 30107-3
Biometric presentation attack detection. Our liveness detection technology is iBeta Level 1 certified under the ISO 30107-3 standard, ensuring reliable detection of spoofing attempts including printed photos, screen replays, and 3D masks.
EU AI Act Ready
Responsible AI compliance. Didit’s AI-powered verification systems are designed in alignment with the EU AI Act requirements for high-risk AI systems, including transparency, human oversight mechanisms, data governance, and bias monitoring.
EBA / MiCA compatibility
Remote onboarding, regulator-grade. An independent legal opinion confirms Didit’s remote onboarding meets the EBA Remote Customer Onboarding Guidelines (EBA/GL/2022/15) and is compatible with the EU AML Single Rulebook and MiCA.
See every certification
The complete, always-current list — SOC 2 Type 2 and Type 1, ISO 27001/27017/27018, iBeta Level 1, FSM, the Spanish regulator attestation, EBA/MiCA, and GDPR — with dates and how to get each report. We add more all the time; if you need a specific certification, book a demo and tell us.
Identity verification using biometrics is classified as high-risk under the EU AI Act. Didit proactively addresses these requirements:
Didit continuously updates its compliance posture as the EU AI Act implementing measures are finalized. Contact your Didit representative for the latest AI Act readiness documentation.
Didit acts as a data processor — you remain the data controller. The platform is designed to support GDPR and local data-protection regimes out of the box.
Customer responsibilities in verification flows
When you use Didit in your own onboarding, authentication, or verification experience, you remain responsible for the controller-side disclosures and legal basis for that flow.Need a DPA, TOMs, sub-processor list, or other compliance attestations? Contact your Didit representative or email hello@didit.me.
Security FAQ
What certifications does Didit hold?
What certifications does Didit hold?
Didit is SOC 2 Type 2 certified (July 2026, covering the March 9 – July 1, 2026 observation period; Type 1 issued April 2026), ISO 27001 certified for information security management, ISO 27017 and ISO 27018 certified for cloud security and privacy, fully GDPR compliant, iBeta Level 1 certified (ISO 30107-3) for biometric presentation attack detection, and FSM Jugendschutz geprüft in Germany for age verification under Section 4(2) JMStV. Didit is also the only provider attested by Spanish financial regulators (Tesoro, Banco de España, SEPBLAC, CNMV) as at least as safe as in-person verification, and holds an independent legal opinion confirming EBA/MiCA compatibility. See the complete list on the Certifications page. We add more all the time — if you need a specific certification, book a demo and tell us.
Is my data encrypted?
Is my data encrypted?
Yes. All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. We use industry-standard cryptographic protocols across our entire infrastructure.
Where is data stored and processed?
Where is data stored and processed?
By default, all data is processed and stored in the EU on AWS infrastructure. Enterprise customers can request in-country processing with local data residency options, subject to availability.
How do I configure data retention?
How do I configure data retention?
Navigate to Business Console → App Settings → Data to set your retention window (1 month to 10 years). You can also delete sessions on demand via the Console or Delete Session API. See the Data Retention page for details.
Can I delete verification data?
Can I delete verification data?
Yes. Delete individual sessions through the Console or programmatically via the Delete Session API. For maximum data minimization, use the process-and-purge pattern to remove data immediately after receiving webhook results.
How do you handle security incidents?
How do you handle security incidents?
We maintain a documented incident response plan with defined severity levels, escalation procedures, and communication protocols. Any material incidents are reported to affected customers within the timeframes required by GDPR and applicable regulations.
Is Didit compliant with the EU AI Act?
Is Didit compliant with the EU AI Act?
Didit proactively aligns with the EU AI Act requirements for high-risk AI systems, including risk management, data governance, transparency, human oversight, accuracy testing, and non-discrimination. We continuously update our compliance posture as implementing measures are finalized.
Can I get security documentation?
Can I get security documentation?
Yes. We provide DPAs, TOMs, sub-processor lists, penetration test summaries (under NDA), and ISO certificate excerpts. Contact your Didit representative or email hello@didit.me.
How are audit logs handled?
How are audit logs handled?
Every API call and Console action is recorded with timestamps, user IDs, and IP addresses. Audit logs are retained for 365 days and can be exported at any time. See the Audit Logs page for details.
Related resources
Certifications & attestations
Every credential Didit holds, with dates and how to get each report.
Data Retention
Configure retention policies and implement privacy-first patterns.
Audit Logs
Track every action with complete audit trails.
Webhooks
Receive real-time notifications for verification events.
API Authentication
Secure API key management and authentication.