Skip to content

Trust you can audit

Privy runs identity and signature infrastructure. How that infrastructure is built, governed and examined is part of the product, not a footnote to it. This page sets out what is independently verified, what we do with data, and what we will tell you when something goes wrong.

Independent audits, not self-assessments

Anyone can describe their own security. The statements below are backed by external audit programmes and certification bodies, which means a third party examined the controls and issued a finding.

  • WebTrust

    for Certification Authorities

    An independent audit programme for certificate authorities, covering how digital certificates are issued, managed and revoked.

    Why it matters

    A signature is only as trustworthy as the authority behind the certificate. This is the audit that examines that authority — not a claim Privy makes about itself.

  • ISO/IEC 27001:2022

    certified by TÜV Rheinland

    The international standard for information security management — how security risk is identified, controlled and reviewed.

    Why it matters

    Your security team will ask how risk is governed, not whether a firewall exists. This is the answer they are trained to read, from a certification body they already recognise.

  • ISO/IEC 27701

    certified by BSI

    The privacy extension to ISO/IEC 27001, covering how personal information is handled throughout its life cycle.

    Why it matters

    Identity data is the most sensitive thing a person can hand over. This covers how it is collected, used, retained and deleted — the questions a privacy review actually asks.

  • iBeta Level 2

    presentation attack detection · ISO/IEC 30107-3

    Independent laboratory testing of liveness detection against presentation attacks — recorded faces, masks, replays — to the ISO/IEC 30107-3 standard, at Level 2.

    Why it matters

    Liveness is where identity fraud attacks first. This is an independent lab trying to break it with spoofs and replays — and the check holding, not a vendor benchmark.

Certificate Warranty

Protection beyond the signature

Eligible verified users are protected by Certificate Warranty of up to US$170K*.

*Rounded regional amount. Terms and conditions apply. Available to eligible verified users.

up to US$170K*

Ask our team

Security

Security is managed as a programme with defined controls, owners and review cycles — certified to ISO/IEC 27001:2022.

  • Managed, not improvised

    Risks are identified, assigned an owner, controlled and reviewed on a schedule. The certification covers the management system itself, not a single product feature.

  • Encryption in transit and at rest

    Identity data and documents are encrypted while moving between systems and while stored.

  • Access is least-privilege

    Internal access to customer data is restricted to the roles that need it, and access events are recorded.

Governance

Privy operates as a certificate authority. The way certificates are issued, managed and revoked is audited under the WebTrust programme.

  • Audited certificate operations

    WebTrust for Certification Authorities is an independent audit programme covering the practices behind certificate issuance, lifecycle management and revocation.

  • Accountable decisions

    Actions that affect trust — issuing, suspending or revoking a certificate — are recorded with the authority under which they were taken.

  • Change is controlled

    Changes to infrastructure that carries trust decisions go through review rather than direct modification.

Privacy

Identity data is the most sensitive data a person can share. Handling of personal information is certified to ISO/IEC 27701.

  • Purpose-bound processing

    Personal information is processed for the purpose it was collected for, and that purpose is stated rather than implied.

  • Retention you can configure

    Organisations using Privy can align retention to their own policy rather than accepting a single default.

  • The person keeps control

    Privy Digital Identity is designed so the individual decides which platform receives which attributes, each time.

Auditability

A trust claim you cannot examine later is not much of a claim. Every verification and every signature produces a durable record.

  • A record of what happened

    Each action carries what was done, when, and on whose authority — available when an agreement is questioned, not reconstructed afterwards.

  • Evidence behind a decision

    A verification result is accompanied by the checks that produced it, so a reviewer can see why the system decided as it did.

  • Exportable

    Records can be retrieved for internal review, audit or dispute resolution.

Reviewing Privy as a vendor?

Tell us what your security or procurement team needs to see and we will get you the right documentation.