NewSOC 2 Tipe 1
Audit independen terhadap kontrol keamanan, ketersediaan, dan kerahasiaan kami, diterbitkan oleh ATOM pada April 2026. Pemeriksaan Tipe 2 sedang berlangsung.
Kami mengurus lisensi, anak perusahaan, dan audit agar tim kepatuhan dan risiko Anda bisa bergerak lebih cepat. Cukup aktifkan dan luncurkan di negara mana pun secara patuh, termasuk SOC 2 Type 1, ISO/IEC 27001, dan atestasi pemerintah Tesoro EU.
“Verifikasi NFC + liveness aktif Didit menawarkan keamanan yang setara atau lebih besar dari verifikasi tatap muka.”
November 2024, Juli 2025 · Sandbox financiero (Ley 7/2020), angkatan ke-4 · diawasi oleh Tesoro Público, Banco de España, SEPBLAC, dan CNMV.
Liveness, deteksi deepfake, pengklasifikasi dokumen, pencocokan wajah, deteksi serangan injeksi, risiko perilaku, setiap model ada di pipeline pelatihan dan penyajian kami sendiri.
Traffic produksi mengalir ke antrean peninjauan real-time. Drift, tingkat false-positive, pergeseran pola serangan, dan kualitas sinyal per negara terus dipantau; ambang batas disesuaikan ulang tanpa perubahan kode pelanggan.
Setiap model terintegrasi secara inline pada sesi. Inferensi p99 di bawah 2 detik, tanpa round-trip tambahan, tanpa tap tambahan. Pengguna yang sah menyelesaikan verifikasi dalam alur yang sama; hanya penyerang yang melihat jalur yang berbeda.
NewAudit independen terhadap kontrol keamanan, ketersediaan, dan kerahasiaan kami, diterbitkan oleh ATOM pada April 2026. Pemeriksaan Tipe 2 sedang berlangsung.

Mensertifikasi bahwa manajemen keamanan informasi kami mencakup verifikasi Didit secara menyeluruh. Diterbitkan oleh Bureau Veritas, berlaku hingga Juni 2027.

Uji anti-spoofing biometrik, 360 percobaan di enam kategori serangan, tidak ada yang berhasil. Dilakukan di lab NVLAP terakreditasi NIST 200962.
Sandbox selama setahun oleh empat regulator keuangan Spanyol menyimpulkan bahwa verifikasi jarak jauh Didit setidaknya sama amannya dengan pemeriksaan ID langsung. Tidak ada vendor identitas lain yang memiliki ini.

Kepatuhan penuh terhadap General Data Protection Regulation (GDPR) sebagai Pemroses Data. Perjanjian Pemrosesan Data serta Tindakan Teknis dan Organisasi tersedia berdasarkan permintaan.

Opini hukum independen: Onboarding jarak jauh Didit memenuhi Pedoman Otoritas Perbankan Eropa tentang onboarding pelanggan jarak jauh (EBA/GL/2022/15) dan kompatibel dengan EU Anti-Money Laundering (AML) Single Rulebook serta regulasi Markets in Crypto-Assets (MiCA) yang akan datang.
Setiap sesi dienkripsi saat tidak aktif dengan kunci AES (Advanced Encryption Standard) 256-bit. Kunci-kunci ini tidak pernah menyentuh kode aplikasi kami, mereka berada di AWS KMS (Key Management Service), dengan kunci terpisah untuk sandbox dan produksi.
Setiap panggilan API, webhook, dan sesi Business Console dienkripsi melalui TLS (Transport Layer Security) 1.3 dengan aturan cipher yang ketat. Protokol lama tidak dapat kembali; HSTS (HTTP Strict Transport Security) diberlakukan di seluruh situs.
Sesi diproses dan disimpan di Uni Eropa secara default di AWS. Perusahaan dapat mengaktifkan residensi di negara tertentu, tergantung ketersediaan, sehingga tim di pasar mana pun dapat menjalankan Didit secara patuh.
Pilih berapa lama Didit menyimpan setiap sesi, dari satu bulan hingga sepuluh tahun, per aplikasi di Business Console. Deployment dengan jejak minimal dapat menghapus sesi segera setelah webhook tiba.
Anda memilih data apa saja yang dikumpulkan Didit, yang lainnya akan dihapus. Secara default, hanya template biometrik dan metadata yang disimpan; selfie mentah dan video liveness dihapus segera setelah sesi ditutup.
DSAR (Data Subject Access Request) penuh dan hak untuk dihapus sesuai permintaan melalui API publik. Pengguna akhir mengirim DSAR dari aplikasi Didit Identity; tim Anda memicunya dengan satu panggilan DELETE pada endpoint sesi. Diberlakukan pada setiap replika, tanpa soft-delete, tanpa archive bucket.
Zero data breaches since Didit launched in 2023. Security is built into every layer of the platform.
status.didit.me, every incident, every post-mortem, no login required. 100% uptime over the last 6 months.Request the Trust Pack on this page, SOC 2 report, ISO certificate, iBeta report, Tesoro attestation, Data Processing Agreement (DPA), sub-processors list, sent back the same business day under a signed Non-Disclosure Agreement (NDA).
Yes. The infrastructure scales itself in real time and supports millions of verifications a day.
status.didit.me, no login required.Volume tiers on the pricing page kick in automatically as you grow, no contract change, no manual renegotiation.
You choose, per workflow. Didit does not have a fixed list of what we keep. Your compliance team configures each app in the Business Console, and the workflow only collects and stores what you tell it to.
The Returned-data tab gives you a toggle for every category:
The exact list of toggles depends on the modules in your workflow, check them when you set the workflow up in the Business Console under Returned-data.
You are the Data Controller. Didit is the Data Processor. This is the General Data Protection Regulation (GDPR) Article 28 set-up most regulated buyers expect.
We recommend you let Didit store and access the data on your behalf. Most of our customers do. Securing identity data at internet scale is a full-time job: hardened encryption, key rotation, intrusion detection, vulnerability management, certification renewals, regional residency, data-subject-rights tooling, breach notification. Didit's security and platform teams focus on it every day so your compliance and engineering teams do not have to. You retain full control through the Business Console, every retention rule, every Data Subject Access Request (DSAR), every delete is yours to trigger.
If your policy requires the data to live entirely in your own environment (your cloud account, your on-premise database), we support that too, Didit runs as a processor on a fetch-and-forget basis and your team owns retention end to end.
European Union by default. Specific region or in-country available on Enterprise.
The default deployment runs on Amazon Web Services (AWS) in EU. Data is encrypted at rest and in transit, with encryption keys held by AWS and separated per environment.
When data crosses a border, it is protected by the European Commission's 2021 Standard Contractual Clauses (SCCs). The matching Transfer Impact Assessment (TIA) ships with the Trust Pack on this page.
You set the retention window. From 1 month to 10 years, per app. Enforcement is automatic.
In the Business Console you set:
If you want Didit to keep nothing after the verdict, call POST /v3/sessions/:session_id/delete/ from your webhook handler and the session is gone the moment your system records its own copy of the result, Didit never holds the data past the call. Full reference at docs.didit.me/sessions-api/delete-session.
One endpoint per right.
GET /v3/sessions/:session_id/decision/. Reference at docs.didit.me/sessions-api/retrieve-session.POST /v3/sessions/:session_id/delete/ removes the session and every linked artifact. Reference at docs.didit.me/sessions-api/delete-session.Five external attestations on file. All packaged in the Trust Pack.
ES144068, valid through 2027-06-03).EBA/GL/2022/15) and the MiCA regulation.Request the Trust Pack on this page and we send every report, certificate, and memo back the same business day under a signed Non-Disclosure Agreement (NDA).
Mutual recognition across the European Union (EU), and a regulator-defensible audit trail.
Spain's Tesoro Público, Banco de España, SEPBLAC, and CNMV ran a year-long financial sandbox (November 2024 – July 2025) on Didit's Near-Field Communication (NFC) chip read plus active liveness onboarding flow. The official conclusions report, published on tesoro.es, finds Didit's remote verification meets or exceeds the security level of in-person identification under the Anti-Money Laundering Directive (AMLD).
For your compliance team this means:
Didit is the only identity-verification vendor with this attestation on the public record.
Yes, and we are probably already working on it. Didit is actively pursuing 10+ certifications, licenses, and regulator approvals across markets and verticals at any given time: payment authorisations, crypto and Markets in Crypto-Assets (MiCA) registrations, Anti-Money Laundering (AML) supervisor approvals, eIDAS 2.0 Qualified Trust Service Provider (QTSP) status, regional Financial Intelligence Unit (FIU) reporting, and vertical-specific authorisations (iGaming, healthcare, banking).
If there is a license or certification your compliance team needs Didit to hold, email `security@didit.me`. Odds are it is already in our queue, and if it is not, your request bumps it up the list. We come back with:
Satu API untuk KYC, KYB, Transaction Monitoring, dan Wallet Screening. Integrasi dalam 5 menit.