Security & Compliance

We handle your users' identity data. Here is how.

IDPylon is built with security controls aligned to SOC 2 principles: encryption at rest and in transit, access controls, audit logging, and a configurable data retention model.

Controls in depth

Encryption everywhere

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Document images are encrypted at storage write time and accessible only during active session processing.

Access controls

Role-based access for your team. API keys scoped to permissions. All access events logged with actor, timestamp, and resource.

Data residency

US-based data processing as default. Configurable for EU data residency requirements. We do not cross-region-replicate PII without explicit customer configuration.

Audit logging

Every API call, verification event, and admin action is logged in an append-only audit trail. Exportable in JSON or CSV for your compliance program.

Built with compliance in mind

IDPylon is a bootstrapped company without a third-party audit certificate yet. We designed our infrastructure controls with SOC 2 Type II in mind and are in the process of preparing for our first external audit. We do not claim compliance certifications we have not completed.

  • SOC 2 controls in design (audit in preparation)
  • GDPR-aware data handling architecture
  • CCPA-aligned data subject rights support
  • Configurable PII retention and purge policies
  • Vendor security review process for all sub-processors
  • Incident response runbook in place

Responsible disclosure

Found a vulnerability? Email [email protected] with a description, reproduction steps, and your disclosure timeline. We will acknowledge within 2 business days and work with you on a coordinated disclosure.

Security questions?

We are happy to walk through our architecture and controls with your security team.