Compliance posture
SOC 2
Program in progress — no report issued yet
External auditor engaged; control library in place. Letter of engagement available on request under NDA.
ISO 27001
Planning · no fixed certification date
Scoping ISMS, control mapping, and gap assessment. No fixed certification date.
GDPR / UK GDPR
In progress — not yet aligned
Cookie consent, a documented data-subject-request workflow and a public Records of Processing Activities summary are live. Still open: counsel review of the Privacy Policy, and a Data Processing Agreement — drafted and with counsel, not yet available for signature. We do not claim standard contractual clauses we have not put in place. EU/UK data subjects can exercise rights at [email protected].
CCPA / CPRA
In progress
Privacy notice, cookie consent, a documented request workflow and a public RoPA are live; counsel review of the Privacy Policy is still open. California residents may request access, deletion, or opt-out at [email protected]. We do not sell personal information.
PCI DSS
Out of scope (Stripe)
We never see full card numbers. Stripe handles PAN storage and tokenisation; our environment is PCI-out-of-scope.
Security controls
- Encryption in transitTLS 1.2+ on every public endpoint; mTLS between internal services on Tailscale.
- Encryption at restPostgres + object storage AES-256. KMS-managed keys. CMEK available on Enterprise.
- Access controlSSO/SAML for the dashboard, scoped API keys for the API, full audit log of admin actions.
- Secret managementNo secrets in git. Production credentials in encrypted parameter store, rotated quarterly.
- BackupsDaily encrypted Postgres snapshots, 35-day retention, restore drills monthly.
- Vulnerability managementDependabot + weekly Trivy scan of every container. Critical CVEs patched within 7 days.
- Incident responseContinuous monitoring with on-call paging. We don't publish uptime or response-time figures until we can substantiate them.
Service availability
We publish real-time API and service health at kyt.infinihash.com/status. The page shows current status and latency for every component: KYT screening, KYC, authentication, billing, and the web app.
We don't publish uptime or response-time figures until we can substantiate them. Planned maintenance is announced on the status page ahead of time.
Sub-processors
We use a deliberately small list of sub-processors. The current list:
- · AWS — production hosting (us-east-2)
- · Cloudflare — edge, DNS, DDoS
- · Stripe — billing and PAN storage
- · Anthropic + Google — narrative generation (data is sent only with explicit per-screening opt-in; see Privacy)
- · Postmark — transactional email
Want notice when this list changes? [email protected] — we maintain a notification list.
Reporting a vulnerability
Email [email protected] — PGP key on request. We acknowledge within 24 hours and aim to triage within 72. We do not run a paid bug-bounty yet but credit researchers in our advisories.