Built to satisfy the rule — not just survive the audit.
Othentity sits in a regulated path: agency transmission, identity proofing, and the handling of the most sensitive identifiers there are. We're transparent about where we are today and what's next — pre-seed, with certifications actively in motion.
Where every framework stands today.
Honest status for a company in active development. We update this as milestones complete.
“Aligned” / “designed to” means our controls are built to the standard ahead of formal attestation. Certification artifacts are available in the data room once an access review is complete.
The rules we operate under.
Agency transmission
Returns are e-filed through IRS Modernized e-File (MeF) and FIRE, and to the SSA — the same authoritative channels businesses use today, with Othentity as the authorized layer.
Identity proofing
Proofing is aligned to NIST 800-63A IAL2: a government-ID check plus a liveness test that binds the document to the live person — strong enough to stand behind an authorization.
Financial privacy
As a processor for banks and lenders, we're built to GLBA Safeguards and act under a Data Processing Agreement that defines controller / processor roles.
Consumer privacy
CCPA/CPRA rights — access, deletion, and opt-out — are honored, and individuals can see and revoke every authorization directly.
Biometric handling
Where facial matching is used, we collect standalone consent and follow biometric-privacy laws like BIPA. Templates are encrypted and never shared in raw form.
Attestation roadmap
SOC 2 Type I is the next formal milestone, funded by the current round, followed by Type II once we've operated the controls over a review period.
Minimal collection. Bounded retention. Clear roles.
The vendors in the path — and what they touch.
A representative list. None receive raw identifiers; sensitive data stays inside the Othentity vault boundary.
| Category | Purpose | Sensitive data |
|---|---|---|
| Cloud infrastructure | Compute, storage, and networking for the platform | Encrypted only |
| Key-management service | Managed key custody for the vault (HSM-backed in production) | Keys, never plaintext |
| Identity proofing sources | Government & credential verification (SSA, AAMVA, USPS) — integrations planned | Proofing only |
| Agency gateways | IRS MeF / FIRE and SSA transmission | At filing time |
| Email & notifications | Transactional messages to users and admins | No identifiers |
The complete, current sub-processor list with named vendors is available in the data room.
Want the controls behind the checkmarks?
The security model and the system architecture show how these commitments are enforced.