βœ“ SOC 2 Type II β€” In Progress

SOC 2 Compliance

HumanAttest is actively pursuing SOC 2 Type II certification. This page outlines our current security controls and compliance posture.

Trust Service Criteria

Implemented

Security

Access controls, encryption at rest (AES-256), TLS 1.3 in transit, MFA for all engineers, regular penetration testing.

Implemented

Availability

99.9% uptime SLA, redundant infrastructure, automated failover, incident response procedures.

Implemented

Confidentiality

Zero email content storage, data minimization by design, strict access controls, NDA for all staff.

Implemented

Privacy

GDPR and CCPA compliant, data subject rights portal, privacy-by-design architecture, no data selling.

In Progress

Processing Integrity

Cryptographic audit trail for all verification events, immutable logs, hash verification for recipients.

Current Security Controls

πŸ”

AES-256 Encryption

All data encrypted at rest.

πŸ”’

TLS 1.3

All data encrypted in transit.

πŸ‘€

MFA Required

All engineer accounts require hardware MFA.

πŸ”

Pen Testing

Quarterly third-party penetration tests.

πŸ“‹

Access Logs

All database access is logged and audited.

🚨

Incident Response

24-hour incident response SLA.

Request Security Documentation

Enterprise customers can request our current security documentation, penetration test summaries, and compliance evidence package by contacting our security team.

Contact Security Team β†’

For the full technical security overview, see the Security Whitepaper. For privacy details, see the Privacy Policy.