We handle your users' identity data. Here is how.
IDPylon is built with security controls aligned to SOC 2 principles: encryption at rest and in transit, access controls, audit logging, and a configurable data retention model.
Controls in depth
Encryption everywhere
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Document images are encrypted at storage write time and accessible only during active session processing.
Access controls
Role-based access for your team. API keys scoped to permissions. All access events logged with actor, timestamp, and resource.
Data residency
US-based data processing as default. Configurable for EU data residency requirements. We do not cross-region-replicate PII without explicit customer configuration.
Audit logging
Every API call, verification event, and admin action is logged in an append-only audit trail. Exportable in JSON or CSV for your compliance program.
Built with compliance in mind
IDPylon is a bootstrapped company without a third-party audit certificate yet. We designed our infrastructure controls with SOC 2 Type II in mind and are in the process of preparing for our first external audit. We do not claim compliance certifications we have not completed.
- SOC 2 controls in design (audit in preparation)
- GDPR-aware data handling architecture
- CCPA-aligned data subject rights support
- Configurable PII retention and purge policies
- Vendor security review process for all sub-processors
- Incident response runbook in place
Responsible disclosure
Found a vulnerability? Email [email protected] with a description, reproduction steps, and your disclosure timeline. We will acknowledge within 2 business days and work with you on a coordinated disclosure.
Security questions?
We are happy to walk through our architecture and controls with your security team.