Home/Trust · Compliance
Compliance

Built to satisfy the rule, not just survive the audit.

Othentity sits in a regulated path: agency transmission, identity proofing, and the handling of the most sensitive identifiers there are. We're transparent about where we are today and what's next, pre-seed, with certifications actively in motion.

Proofing standard
NIST 800-63A-4 aligned
Agency channels
IRS · SSA
SOC 2
In progress
Status

Where every framework stands today.

Honest status for a company in active development. We update this as milestones complete.

IRS IRIS transmitterIRIS Transmitter Control Code, e-file 1099 information returns (IRIS supersedes the retiring FIRE)In certification
SSA wage reportingBusiness Services Online (EFW2), W-2 wage reports to the Social Security AdministrationIn certification
NIST SP 800-63A-4 IAL2Remote identity proofing, biometric, non-biometric, or digital-evidence pathwaysIn review
SOC 2 Type ISecurity, availability & confidentiality controlsIn progress
SOC 2 Type IIOperating effectiveness over a review periodPlanned
GLBA SafeguardsProtection of financial customer informationDesigned to
CCPA / CPRACalifornia consumer privacy rightsDesigned to
BIPA & biometric lawsConsent & handling for facial-match proofingDesigned to
GDPR readinessFor future cross-border expansionReadiness

“Aligned” / “designed to” means our controls are built to the standard ahead of formal attestation. Certification artifacts are available in the data room once an access review is complete.

Regulatory framework

The rules we operate under.

Agency transmission

W-2 wage reports are filed to the SSA through Business Services Online (EFW2); 1099 information returns are e-filed to the IRS through IRIS, which supersedes the retiring FIRE system. These are the same authoritative channels businesses use today, with Othentity as the authorized layer.

Identity proofing

Proofing is designed to align with NIST SP 800-63A-4 IAL2, which supports biometric, non-biometric, and digital-evidence pathways rather than a single fixed method. Formal control mapping and conformance review are in progress.

Financial privacy

As a processor for banks and lenders, we're built to GLBA Safeguards and act under a Data Processing Agreement that defines controller / processor roles.

Consumer privacy

CCPA/CPRA rights, access, deletion, and opt-out, are honored, and individuals can see and revoke every authorization directly.

Biometric handling

Where facial matching is used, we collect standalone consent and follow biometric-privacy laws like BIPA. Templates are encrypted and never shared in raw form.

Attestation roadmap

SOC 2 Type I is the next formal milestone, funded by the current round, followed by Type II once we've operated the controls over a review period.

Data handling

Minimal collection. Bounded retention. Clear roles.

RolesOthentity acts as a processor; the business is the controller. A standard DPA sets out security measures, sub-processing, and data-subject rights handling.
Data minimizationWe collect only what's required to verify identity and complete a filing. Partners hold tokens, not identifiers.
RetentionRecords are retained only as long as required by applicable financial regulations, then purged. Resolution mappings are not retained beyond their purpose.
Data residencyPrimary infrastructure is hosted in the United States (us-east-1). Regional residency is available for enterprise tenants.
Individual rightsPeople can view their full audit log, see every active authorization, and revoke any of them instantly through the customer dashboard.
Examination support

When an examiner comes knocking, the records are there.

Statutory recordkeeping does not disappear because the SSN lives in one vault instead of a dozen databases. If the IRS or SSA examines a partner, that partner must still produce complete records within the examination timeline, so Othentity, as the authorized agent and system of record, is built to retrieve and produce them.

RequestAn authorized operator at the partner requests the underlying records for a named person or filing through the console or API.
Authorization & auditThe request, its purpose, and the examination reference are logged to the tenant's append-only audit lane before anything is released.
ProductionThe true, unredacted document is released to the partner or produced directly to the examiner, with a preserved chain of custody, inside the exam's response window.
RetentionRecords subject to statutory retention are held for the required period even after an authorization is revoked; revocation ends new actions, not lawful recordkeeping.
Sub-processors

The vendors in the path, and what they touch.

A representative list. None receive raw identifiers; sensitive data stays inside the Othentity vault boundary.

CategoryPurposeSensitive data
Cloud infrastructureCompute, storage, and networking for the platformEncrypted only
Key-management serviceManaged key custody for the vault (HSM-backed in production)Keys, never plaintext
Identity proofing sourcesGovernment & credential verification (SSA, AAMVA, USPS), integrations plannedProofing only
Agency gatewaysSSA Business Services Online (W-2) and IRS IRIS (1099) transmissionAt filing time
Email & notificationsTransactional messages to users and adminsNo identifiers

The complete, current sub-processor list with named vendors is available in the data room.

Keep reading

Want the controls behind the checkmarks?

The security model and the system architecture show how these commitments are enforced.