Home/Trust · Compliance
Compliance

Built to satisfy the rule — not just survive the audit.

Othentity sits in a regulated path: agency transmission, identity proofing, and the handling of the most sensitive identifiers there are. We're transparent about where we are today and what's next — pre-seed, with certifications actively in motion.

Proofing standard
NIST IAL2-aligned
Agency channels
IRS · SSA
SOC 2
In progress
Status

Where every framework stands today.

Honest status for a company in active development. We update this as milestones complete.

IRS authorized transmitterMeF & FIRE — e-file W-2 / 1099 returns In certification
SSA transmissionWage reporting to the Social Security Administration In certification
NIST 800-63A IAL2Remote identity proofing — gov ID + liveness Aligned
SOC 2 Type ISecurity, availability & confidentiality controls In progress
SOC 2 Type IIOperating effectiveness over a review period Planned
GLBA SafeguardsProtection of financial customer information Designed to
CCPA / CPRACalifornia consumer privacy rights Designed to
BIPA & biometric lawsConsent & handling for facial-match proofing Designed to
GDPR readinessFor future cross-border expansion Readiness

“Aligned” / “designed to” means our controls are built to the standard ahead of formal attestation. Certification artifacts are available in the data room once an access review is complete.

Regulatory framework

The rules we operate under.

Agency transmission

Returns are e-filed through IRS Modernized e-File (MeF) and FIRE, and to the SSA — the same authoritative channels businesses use today, with Othentity as the authorized layer.

Identity proofing

Proofing is aligned to NIST 800-63A IAL2: a government-ID check plus a liveness test that binds the document to the live person — strong enough to stand behind an authorization.

Financial privacy

As a processor for banks and lenders, we're built to GLBA Safeguards and act under a Data Processing Agreement that defines controller / processor roles.

Consumer privacy

CCPA/CPRA rights — access, deletion, and opt-out — are honored, and individuals can see and revoke every authorization directly.

Biometric handling

Where facial matching is used, we collect standalone consent and follow biometric-privacy laws like BIPA. Templates are encrypted and never shared in raw form.

Attestation roadmap

SOC 2 Type I is the next formal milestone, funded by the current round, followed by Type II once we've operated the controls over a review period.

Data handling

Minimal collection. Bounded retention. Clear roles.

RolesOthentity acts as a processor; the business is the controller. A standard DPA sets out security measures, sub-processing, and data-subject rights handling.
Data minimizationWe collect only what's required to verify identity and complete a filing. Partners hold tokens, not identifiers.
RetentionRecords are retained only as long as required by applicable financial regulations, then purged. Resolution mappings are not retained beyond their purpose.
Data residencyPrimary infrastructure is hosted in the United States (us-east-1). Regional residency is available for enterprise tenants.
Individual rightsPeople can view their full audit log, see every active authorization, and revoke any of them instantly through the customer dashboard.
Sub-processors

The vendors in the path — and what they touch.

A representative list. None receive raw identifiers; sensitive data stays inside the Othentity vault boundary.

CategoryPurposeSensitive data
Cloud infrastructureCompute, storage, and networking for the platformEncrypted only
Key-management serviceManaged key custody for the vault (HSM-backed in production)Keys, never plaintext
Identity proofing sourcesGovernment & credential verification (SSA, AAMVA, USPS) — integrations plannedProofing only
Agency gatewaysIRS MeF / FIRE and SSA transmissionAt filing time
Email & notificationsTransactional messages to users and adminsNo identifiers

The complete, current sub-processor list with named vendors is available in the data room.

Keep reading

Want the controls behind the checkmarks?

The security model and the system architecture show how these commitments are enforced.