Built to satisfy the rule, not just survive the audit.
Othentity sits in a regulated path: agency transmission, identity proofing, and the handling of the most sensitive identifiers there are. We're transparent about where we are today and what's next, pre-seed, with certifications actively in motion.
Where every framework stands today.
Honest status for a company in active development. We update this as milestones complete.
“Aligned” / “designed to” means our controls are built to the standard ahead of formal attestation. Certification artifacts are available in the data room once an access review is complete.
The rules we operate under.
Agency transmission
W-2 wage reports are filed to the SSA through Business Services Online (EFW2); 1099 information returns are e-filed to the IRS through IRIS, which supersedes the retiring FIRE system. These are the same authoritative channels businesses use today, with Othentity as the authorized layer.
Identity proofing
Proofing is designed to align with NIST SP 800-63A-4 IAL2, which supports biometric, non-biometric, and digital-evidence pathways rather than a single fixed method. Formal control mapping and conformance review are in progress.
Financial privacy
As a processor for banks and lenders, we're built to GLBA Safeguards and act under a Data Processing Agreement that defines controller / processor roles.
Consumer privacy
CCPA/CPRA rights, access, deletion, and opt-out, are honored, and individuals can see and revoke every authorization directly.
Biometric handling
Where facial matching is used, we collect standalone consent and follow biometric-privacy laws like BIPA. Templates are encrypted and never shared in raw form.
Attestation roadmap
SOC 2 Type I is the next formal milestone, funded by the current round, followed by Type II once we've operated the controls over a review period.
Minimal collection. Bounded retention. Clear roles.
When an examiner comes knocking, the records are there.
Statutory recordkeeping does not disappear because the SSN lives in one vault instead of a dozen databases. If the IRS or SSA examines a partner, that partner must still produce complete records within the examination timeline, so Othentity, as the authorized agent and system of record, is built to retrieve and produce them.
The vendors in the path, and what they touch.
A representative list. None receive raw identifiers; sensitive data stays inside the Othentity vault boundary.
| Category | Purpose | Sensitive data |
|---|---|---|
| Cloud infrastructure | Compute, storage, and networking for the platform | Encrypted only |
| Key-management service | Managed key custody for the vault (HSM-backed in production) | Keys, never plaintext |
| Identity proofing sources | Government & credential verification (SSA, AAMVA, USPS), integrations planned | Proofing only |
| Agency gateways | SSA Business Services Online (W-2) and IRS IRIS (1099) transmission | At filing time |
| Email & notifications | Transactional messages to users and admins | No identifiers |
The complete, current sub-processor list with named vendors is available in the data room.
Want the controls behind the checkmarks?
The security model and the system architecture show how these commitments are enforced.