Security & Compliance

Built for regulated
industries, from day one.

When you process biometric PII, you need a vendor you can trust. Here is exactly what we have in place today — and what's still ahead.

TLS encryption in transit

All API traffic is encrypted end-to-end. No plain-text data ever leaves your server or ours.

GDPR compliant

Right to access (Art. 15) and right to erasure (Art. 17) are implemented and live — not planned.

Cloud infrastructure

Hosted on enterprise-grade cloud infrastructure with encrypted data at rest. No biometric raw media retained after processing.

Per-key rate limiting

Every API key has its own request quota enforced in real time. Abuse is blocked before it reaches your data.

We are not yet SOC 2 certified — we will be transparent about that. SOC 2 Type I audit is in our roadmap for 2026. If your compliance team needs to review our security posture in the meantime, reach out directly.
How We Handle Biometric Data

Mathematical representations.
Never raw media at rest.

Biometric data is stored as embeddings — not raw images or audio recordings — on encrypted, enterprise-grade cloud infrastructure. Your compliance team controls the decision threshold; we never make the final access call.

No raw media retained

Face and voice inputs are converted to mathematical embeddings at capture time. Raw frames and audio are discarded after processing.

Encrypted at rest & in transit

All stored embeddings and metadata live on encrypted cloud infrastructure. All API traffic runs over TLS.

User-controlled deletion

Users can request full export or permanent deletion of their data at any time, honoring GDPR Art. 15 & 17 in full.

Security FAQ

Questions compliance teams
ask first.

Where is our users' biometric data stored?

Biometric data is stored as mathematical representations — not raw images or audio recordings. All data is hosted on encrypted, enterprise-grade cloud infrastructure. Users can request full export or permanent deletion of their data at any time (GDPR Art. 15 & 17).

Are you SOC 2 certified?

Not yet — we say this plainly. SOC 2 Type I is on our 2026 roadmap. Today we are GDPR compliant with implemented data rights, TLS encryption, and access controls. If your compliance team needs a security review before then, contact us and we will make it work.

Who owns the final access decision — you or us?

You do. Every verification returns a structured confidence score, not just pass/fail. Your team sets the decision threshold and controls the override process end-to-end.

Need a security review?

Send our team your compliance questionnaire directly — we respond fast and won't hide what's still on the roadmap.