Skip to content

Trust Center

What we commit to, what we've certified, and how to ask for proof.

Compliance posture

SOC 2

Program in progress — no report issued yet

External auditor engaged; control library in place. Letter of engagement available on request under NDA.

ISO 27001

Planning · no fixed certification date

Scoping ISMS, control mapping, and gap assessment. No fixed certification date.

GDPR / UK GDPR

In progress — not yet aligned

Cookie consent, a documented data-subject-request workflow and a public Records of Processing Activities summary are live. Still open: counsel review of the Privacy Policy, and a Data Processing Agreement — drafted and with counsel, not yet available for signature. We do not claim standard contractual clauses we have not put in place. EU/UK data subjects can exercise rights at [email protected].

CCPA / CPRA

In progress

Privacy notice, cookie consent, a documented request workflow and a public RoPA are live; counsel review of the Privacy Policy is still open. California residents may request access, deletion, or opt-out at [email protected]. We do not sell personal information.

PCI DSS

Out of scope (Stripe)

We never see full card numbers. Stripe handles PAN storage and tokenisation; our environment is PCI-out-of-scope.

Security controls

  • Encryption in transitTLS 1.2+ on every public endpoint; mTLS between internal services on Tailscale.
  • Encryption at restPostgres + object storage AES-256. KMS-managed keys. CMEK available on Enterprise.
  • Access controlSSO/SAML for the dashboard, scoped API keys for the API, full audit log of admin actions.
  • Secret managementNo secrets in git. Production credentials in encrypted parameter store, rotated quarterly.
  • BackupsDaily encrypted Postgres snapshots, 35-day retention, restore drills monthly.
  • Vulnerability managementDependabot + weekly Trivy scan of every container. Critical CVEs patched within 7 days.
  • Incident responseContinuous monitoring with on-call paging. We don't publish uptime or response-time figures until we can substantiate them.

Service availability

We publish real-time API and service health at kyt.infinihash.com/status. The page shows current status and latency for every component: KYT screening, KYC, authentication, billing, and the web app.

We don't publish uptime or response-time figures until we can substantiate them. Planned maintenance is announced on the status page ahead of time.

Sub-processors

We use a deliberately small list of sub-processors. The current list:

  • · AWS — production hosting (us-east-2)
  • · Cloudflare — edge, DNS, DDoS
  • · Stripe — billing and PAN storage
  • · Anthropic + Google — narrative generation (data is sent only with explicit per-screening opt-in; see Privacy)
  • · Postmark — transactional email

Want notice when this list changes? [email protected] — we maintain a notification list.

Reporting a vulnerability

Email [email protected] — PGP key on request. We acknowledge within 24 hours and aim to triage within 72. We do not run a paid bug-bounty yet but credit researchers in our advisories.

Need our Security Questionnaire (SIG-Lite, CAIQ), DPA, or pen-test summary? Email [email protected] with the artefact you need; turnaround is usually a business day.
Trust Center | Infinihash