Security & compliance

Security is our product.

We verify identities for a living. That means our own security must be beyond question.

SOC 2 In Progress
Type II target Q1 2027
GDPR
Article 15, 17, 7(3) compliant
CCPA / CPRA
Consumer deletion via Privacy Portal
BIPA
Consent records, 7-year retention
W3C Verifiable Credentials
Signed, offline-verifiable credentials
Posture

Controls implemented today.

Every item below is live in production. Not planned, not in progress.

Authentication
Strong password policy with automatic lockout protection
Immediate session revocation on logout
TOTP/MFA (RFC 6238), per-user opt-in and org-level enforcement
API security
API keys stored as SHA-256 hashes; plaintext never stored
API key expiration (configurable TTL)
IP allowlisting per API key
Aggressive rate limiting on every surface
Transport & headers
TLS enforcement with HSTS
Strict browser security headers (frame denial, content-type sniffing protection, CSP)
Data protection
AES-256-GCM field-level encryption for PII at rest
Database SSL in production
Biometric data never stored; certified provider only
SHA-256 consent text hashing for tamper-evident records
Observability
Structured logging with per-request correlation IDs
A comprehensive audit event taxonomy across the full agent lifecycle
Append-only audit log with a 7-year retention policy
KYA: agent security
Cloud attestation verified against each provider's signed evidence (AWS, GCP, Azure)
Operator accountability chain: cascade suspension on human credential revocation
Agent lifecycle enforcement: retired agents cannot issue new sessions
Automatic re-verification on material agent changes
W3C Verifiable Credentials: offline-verifiable agent identity
Sub-agent delegation off by default; children capped by the parent's trust and scopes, bounded depth, cascade suspension
Privacy & compliance
GDPR Article 15 (access) and 17 (erasure) via Privacy Portal
CCPA consumer deletion requests
BIPA informed consent with SHA-256 consent hash
Automated data anonymization on a scheduled retention cycle

The full controls reference is in the docs. Sign in to read it. Operational specifics are shared with customers under NDA.

Request our SOC 2 Readiness Document

The full readiness report is available to prospects and customers under NDA.

Email security@eniyantrust.com