Skip to main content
Didit Raises $2M and Joins Y Combinator (W26)
Didit
Trust

We carry the compliance. Launch identity checks in one click

We handle the licenses, subsidiaries, and audits so your compliance and risk team can move faster. Flip a switch and launch in any country compliantly — SOC 2 Type 1, ISO/IEC 27001, and the Tesoro EU government attestation included.

By the numbers

By the numbers
  • 0%
    Real uptime over the last 12 months. Logged live at status.didit.me against the 99.99% SLO (Service Level Objective).
  • 0
    Material breaches since Didit launched. Battle-tested in production since 2023.
  • Millions
    Humans verified every month on the production fleet.
  • Certified
    Compliant everywhere Didit operates — SOC 2 Type 1, ISO/IEC 27001, iBeta Level 1 PAD, and Spain's regulator attestation.
Public record

Regulators say Didit is safer than in-person verification.

Spain stress-tested Didit's remote Near-Field Communication (NFC) chip read plus active liveness and put it on the public record as at least as safe as checking an ID in person. No other identity provider holds this attestation.
Supervised by
  • Tesoro Público — Spanish Treasury
  • Banco de España — Bank of Spain
  • SEPBLAC — Spanish financial intelligence unit
  • CNMV — Comisión Nacional del Mercado de Valores
Didit's NFC + active liveness verification offers security equivalent to or greater than in-person verification.
Spanish Treasury — Informe de Conclusiones DIDIT, February 2026

November 2024 – July 2025 · Sandbox financiero (Ley 7/2020), 4th cohort · supervised by Tesoro Público, Banco de España, SEPBLAC, and CNMV.

Fraud engineering

A dedicated fraud team. Models, monitoring, prevention.

A team focused only on fraud builds, trains, and monitors the detection models behind every Didit session — deepfakes, injection attacks, forgeries, synthetic identities, money mules. New attack in the wild? New signal that week. Legitimate users never feel it.
  • Models — built and retrained in-house.

    Liveness, deepfake detection, document classifiers, face match, injection-attack detection, behavioural risk — every model lives in our own training and serving pipeline.

  • Monitoring — every session, every hour.

    Production traffic feeds a real-time review queue. Drift, false-positive rate, attack-pattern shifts and per-country signal quality are watched continuously; thresholds are re-tuned without a customer code change.

  • Prevention — inline, invisible to the user.

    Every model integrates inline on the session. Sub-2-second p99 inference, no extra round-trip, no extra tap. The legitimate user finishes verification in the same flow; only the attacker sees a different path.

Certifications

Every claim has a document behind it.

Six external attestations covering security, privacy, biometric anti-spoofing, regulatory adequacy, and government recognition. Every card delivers a real document — not a marketing PDF.
SOC 2 Type 1 attestation badgeNew
AICPA · 2026-04-09

SOC 2 Type 1

Independent audit of our security, availability, and confidentiality controls — issued by ATOM in April 2026. Type 2 examination underway.

ISO 27001 certificate issued by Bureau Veritas
ES144068 · Bureau Veritas

ISO/IEC 27001:2022

Certifies that our information-security management covers Didit verifications end to end. Issued by Bureau Veritas, valid through June 2027.

iBeta Level 1 PAD compliant badge
ISO/IEC 30107-3 · NIST/NVLAP

iBeta Level 1 PAD

Biometric anti-spoofing test — 360 attempts across six attack categories, zero got through. Conducted at NIST-accredited NVLAP lab 200962.

Tesoro Público — Spanish Treasury wordmark
Spain · CNMV · SEPBLAC · BdE

Tesoro sandbox attestation

A year-long sandbox by four Spanish financial regulators concluded Didit's remote verification is at least as safe as in-person ID checks. No other identity vendor holds this.

GDPR Ready badge
EU 2016/679 · DPA · TOMs

GDPR Article 32

Full General Data Protection Regulation (GDPR) compliance as a Data Processor. Data Processing Agreement and Technical and Organisational Measures available on request.

EBA / MiCA compliance badge
EBA/GL/2022/15 · MiCA

EBA / MiCA compliance

Independent legal opinion: Didit's remote onboarding meets the European Banking Authority Guidelines on remote customer onboarding (EBA/GL/2022/15) and is compatible with the incoming EU Anti-Money Laundering (AML) Single Rulebook and the Markets in Crypto-Assets (MiCA) regulation.

Data protection

What we store, where we store it, how long we keep it.

You own the data; Didit processes it on your behalf. Under GDPR (General Data Protection Regulation) you're the Data Controller and Didit is the Data Processor. The platform ships with GDPR Article 32 controls and local data-protection rules already wired in.
  • Encryption at restAES-256.

    Every session is encrypted at rest with 256-bit AES (Advanced Encryption Standard) keys. The keys never touch our application code — they live in AWS KMS (Key Management Service), with separate keys for sandbox and production.

  • Encryption in transitTLS 1.3.

    Every API call, webhook, and Business Console session is encrypted over TLS (Transport Layer Security) 1.3 with strict cipher rules. Older protocols can't fall back in; HSTS (HTTP Strict Transport Security) is enforced site-wide.

  • Data residencyEU by default.

    Sessions are processed and stored in the European Union by default on AWS. Enterprise can enable in-country residency, subject to availability — so teams in any market run Didit compliantly.

  • Retention1 month to 10 years.

    Pick how long Didit keeps each session — from one month to ten years — per app in the Business Console. Minimal-footprint deployments can delete the session as soon as the webhook lands.

  • Biometric handlingData minimization.

    You choose exactly which data Didit collects — everything else is dropped. By default only biometric templates and metadata are kept; raw selfies and liveness video are deleted the moment the session closes.

  • Data subject rightsDelete data with one endpoint.

    Full DSAR (Data Subject Access Request) and right-to-erasure on demand via the public API. End users send DSARs from the Didit Identity app; your team triggers them with one DELETE call on the sessions endpoint. Enforced on every replica — no soft-delete, no archive bucket.

FAQ

Security questions, answered.

The same answers we send to enterprise security teams. Anything else — security@didit.me.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page