Skip to content

Trust you can audit

Privy runs identity and signature infrastructure. How that infrastructure is built, governed and examined is part of the product, not a footnote to it. This page sets out what is independently verified, what we do with data, and what we will tell you when something goes wrong.

Independent audits, not self-assessments

Anyone can describe their own security. The statements below are backed by external audit programmes and certification bodies, which means a third party examined the controls and issued a finding.

  • WebTrust

    for Certification Authorities

    An independent audit programme for certificate authorities, covering how digital certificates are issued, managed and revoked.

    Why it matters

    A signature is only as trustworthy as the authority behind the certificate. This is the audit that examines that authority — not a claim Privy makes about itself.

  • ISO/IEC 27001:2022

    certified by TÜV Rheinland

    The international standard for information security management — how security risk is identified, controlled and reviewed.

    Why it matters

    Your security team will ask how risk is governed, not whether a firewall exists. This is the answer they are trained to read, from a certification body they already recognise.

  • ISO/IEC 27701

    certified by BSI

    The privacy extension to ISO/IEC 27001, covering how personal information is handled throughout its life cycle.

    Why it matters

    Identity data is the most sensitive thing a person can hand over. This covers how it is collected, used, retained and deleted — the questions a privacy review actually asks.

  • iBeta Level 2

    presentation attack detection · ISO/IEC 30107-3

    Independent laboratory testing of liveness detection against presentation attacks — recorded faces, masks, replays — to the ISO/IEC 30107-3 standard, at Level 2.

    Why it matters

    Liveness is where identity fraud attacks first. This is an independent lab trying to break it with spoofs and replays — and the check holding, not a vendor benchmark.

Certification scope, covered entity and validity dates are being confirmed and will be published here. If you need the current documentation for a procurement or vendor review, ask us and we will send what applies to your evaluation.

Certificate Warranty

Protection beyond the signature

Eligible verified users are protected by Certificate Warranty of up to US$170K*.

*Rounded regional amount. Terms and conditions apply. Available to eligible verified users.

up to US$170K*

Ask our team

Security

Security is managed as a programme with defined controls, owners and review cycles — certified to ISO/IEC 27001:2022.

  • Managed, not improvised

    Risks are identified, assigned an owner, controlled and reviewed on a schedule. The certification covers the management system itself, not a single product feature.

  • Encryption in transit and at rest

    Identity data and documents are encrypted while moving between systems and while stored.

  • Access is least-privilege

    Internal access to customer data is restricted to the roles that need it, and access events are recorded.

Governance

Privy operates as a certificate authority. The way certificates are issued, managed and revoked is audited under the WebTrust programme.

  • Audited certificate operations

    WebTrust for Certification Authorities is an independent audit programme covering the practices behind certificate issuance, lifecycle management and revocation.

  • Accountable decisions

    Actions that affect trust — issuing, suspending or revoking a certificate — are recorded with the authority under which they were taken.

  • Change is controlled

    Changes to infrastructure that carries trust decisions go through review rather than direct modification.

Privacy

Identity data is the most sensitive data a person can share. Handling of personal information is certified to ISO/IEC 27701.

  • Purpose-bound processing

    Personal information is processed for the purpose it was collected for, and that purpose is stated rather than implied.

  • Retention you can configure

    Organisations using Privy can align retention to their own policy rather than accepting a single default.

  • The person keeps control

    Privy Digital Identity is designed so the individual decides which platform receives which attributes, each time.

Auditability

A trust claim you cannot examine later is not much of a claim. Every verification and every signature produces a durable record.

  • A record of what happened

    Each action carries what was done, when, and on whose authority — available when an agreement is questioned, not reconstructed afterwards.

  • Evidence behind a decision

    A verification result is accompanied by the checks that produced it, so a reviewer can see why the system decided as it did.

  • Exportable

    Records can be retrieved for internal review, audit or dispute resolution.

Reviewing Privy as a vendor?

Tell us what your security or procurement team needs to see and we will get you the right documentation.