NewDidit이 규제 준수를 책임집니다. 단 한 번의 클릭
Didit이 라이선스, 자회사, 감사 업무를 처리하여 고객사의 규제 준수 및 리스크 관리팀이 더 빠르게 움직일 수 있도록 돕습니다. 스위치를 켜듯 간편하게 모든 국가에서 규제 준수 요건을 충족하며 서비스를 시작하세요. SOC 2 Type 1, ISO/IEC 27001, Tesoro EU 정부 인증이 포함됩니다.
수치로 보는 Didit
- 0%지난 12개월간 실제 가동 시간. 99.99% SLO(서비스 수준 목표) 대비 status.didit.me에서 실시간으로 기록됩니다.
- 0Didit 출시 이후 중대한 보안 침해 사고는 없었습니다. 2023년부터 프로덕션 환경에서 검증되었습니다.
- 수백만 건매월 프로덕션 환경에서 인증되는 사용자 수.
- 인증 완료Didit이 운영되는 모든 곳에서 규제 준수 인증 완료, SOC 2 Type 1, ISO/IEC 27001, iBeta Level 1 PAD, 스페인 규제 기관 인증.
규제 기관은 Didit이 대면 인증보다 안전하다고 평가합니다.
“Didit의 NFC + 능동형 라이브니스 인증은 대면 인증과 동등하거나 그 이상의 보안 수준을 제공합니다.”
2024년 11월, 2025년 7월 · Sandbox financiero (Ley 7/2020), 4차 코호트 · Tesoro Público, Banco de España, SEPBLAC, CNMV 감독.
전담 사기 방지 팀. 모델, 모니터링, 예방.
자체 구축 및 재학습 모델
라이브니스, 딥페이크 감지, 문서 분류기, 얼굴 매칭, 인젝션 공격 감지, 행동 위험 등 모든 모델은 Didit의 자체 학습 및 서비스 파이프라인에서 운영됩니다.
모니터링, 매 시간, 모든 세션
실시간 트래픽은 실시간 검토 큐에 공급됩니다. 드리프트, 오탐율, 공격 패턴 변화 및 국가별 신호 품질을 지속적으로 모니터링하며, 고객 코드 변경 없이 임계값을 재조정합니다.
예방, 인라인, 사용자에게는 보이지 않게
모든 모델은 세션에 인라인으로 통합됩니다. 2초 미만의 p99 추론, 추가 왕복 없음, 추가 탭 없음. 정상적인 사용자는 동일한 흐름에서 인증을 완료하며, 공격자만 다른 경로를 거칩니다.
모든 주장은 문서로 뒷받침됩니다.
New
ISO/IEC 27001:2022
Didit 검증의 엔드 투 엔드 정보 보안 관리를 인증합니다. Bureau Veritas 발행, 2027년 6월까지 유효합니다.

iBeta Level 1 PAD
생체 인식 위조 방지 테스트, 6가지 공격 카테고리에 걸쳐 360번의 시도에도 불구하고 뚫리지 않았습니다. NIST 공인 NVLAP 연구소 200962에서 수행되었습니다.
Tesoro 샌드박스 증명
스페인 4개 금융 규제 기관의 1년간 샌드박스 결과, Didit의 원격 검증이 대면 신분증 확인만큼 안전하다는 결론이 나왔습니다. 다른 어떤 신원 확인 공급업체도 이 인증을 보유하고 있지 않습니다.

GDPR 제32조
데이터 처리자로서 일반 데이터 보호 규정(GDPR)을 완벽하게 준수합니다. 데이터 처리 계약 및 기술적, 조직적 조치는 요청 시 제공됩니다.

EBA / MiCA 규정 준수
독립적인 법률 자문: Didit의 원격 온보딩은 원격 고객 온보딩에 대한 유럽 은행 당국 지침(EBA/GL/2022/15)을 충족하며, 곧 시행될 EU 자금세탁방지(AML) 단일 규정집 및 암호자산 시장(MiCA) 규정과 호환됩니다.
무엇을, 어디에, 얼마나 오래 보관하는가.
저장 데이터 암호화 — AES-256.
모든 세션은 256비트 AES(Advanced Encryption Standard) 키로 저장 시 암호화됩니다. 키는 애플리케이션 코드에 직접 닿지 않으며, AWS KMS(Key Management Service)에 저장되며 샌드박스 및 프로덕션용으로 별도의 키를 사용합니다.
전송 데이터 암호화 — TLS 1.3.
모든 API 호출, 웹훅 및 비즈니스 콘솔 세션은 엄격한 암호 규칙을 가진 TLS(Transport Layer Security) 1.3을 통해 암호화됩니다. 이전 프로토콜은 대체될 수 없으며, HSTS(HTTP Strict Transport Security)가 사이트 전체에 적용됩니다.
데이터 상주 — 기본값은 EU.
세션은 기본적으로 AWS의 유럽 연합에서 처리 및 저장됩니다. 엔터프라이즈 고객은 가용성에 따라 국내 상주를 활성화할 수 있으므로, 모든 시장의 팀이 Didit을 규정 준수하게 운영할 수 있습니다.
데이터 보존 — 1개월에서 10년까지.
비즈니스 콘솔에서 앱별로 Didit이 각 세션을 보관할 기간(1개월에서 10년까지)을 선택하세요. 최소한의 설치 공간을 사용하는 배포는 웹훅이 도착하는 즉시 세션을 삭제할 수 있습니다.
생체 데이터 처리 — 데이터 최소화.
Didit이 수집할 데이터를 정확히 선택할 수 있으며, 그 외의 모든 데이터는 삭제됩니다. 기본적으로 생체 템플릿과 메타데이터만 보관되며, 원본 셀카 및 라이브니스 비디오는 세션이 종료되는 즉시 삭제됩니다.
데이터 주체 권리 — 하나의 엔드포인트로 데이터 삭제.
공개 API를 통해 DSAR(데이터 주체 접근 요청) 및 삭제 권리를 온디맨드로 제공합니다. 최종 사용자는 Didit Identity 앱에서 DSAR을 전송하고, 팀은 세션 엔드포인트에 대한 DELETE 호출 하나로 이를 트리거합니다. 모든 복제본에 적용되며, 소프트 삭제나 아카이브 버킷은 없습니다.
보안 관련 질문에 답변해 드립니다.
How secure is Didit?
Zero data breaches since Didit launched in 2023. Security is built into every layer of the platform.
- Zero breaches, across millions of verifications and 1,500+ paying customers.
- Everything is encrypted, both when data is stored and when it moves between systems. Encryption keys live in Amazon Web Services (AWS), separated so a sandbox cannot read production data.
- Every request is checked. Every action is logged. No shared secrets across customers.
- Independently audited, SOC 2 Type 1 (Type 2 in progress), ISO/IEC 27001:2022, and iBeta Level 1 Presentation Attack Detection (PAD) with 0% attack-success across 360 attempts.
- Live public status page at
status.didit.me, every incident, every post-mortem, no login required. 100% uptime over the last 6 months. - If anything happens, we tell you within hours, well inside the General Data Protection Regulation (GDPR) Article 33 reporting window. Enterprise gets a named engineer on call 24/7, with a dedicated Slack and WhatsApp channel.
Request the Trust Pack on this page, SOC 2 report, ISO certificate, iBeta report, Tesoro attestation, Data Processing Agreement (DPA), sub-processors list, sent back the same business day under a signed Non-Disclosure Agreement (NDA).
I have lots of verifications. Will Didit support my volume?
Yes. The infrastructure scales itself in real time and supports millions of verifications a day.
- Scales automatically. When your traffic doubles overnight, the platform expands itself. No sales call, no capacity-plan rewrite, no warning needed.
- Every check completes in under 2 seconds, even at peak load. The infrastructure is optimised for fast inference end to end.
- 100% uptime over the last 6 months. Track it live at
status.didit.me, no login required. - Battle-tested in production, 1,500+ paying customers across 220+ countries, in production since 2023.
- Built for spike events, sports-betting kick-offs, marketplace launches, age-verification rollouts. The platform handles the spike without anyone at Didit having to lift a finger.
- Enterprise contracts include written guarantees, a Service Level Agreement (SLA) on speed, uptime, and capacity, with billing credits if we miss.
Volume tiers on the pricing page kick in automatically as you grow, no contract change, no manual renegotiation.
What data does Didit store, and how much control do I have over it?
You choose, per workflow. Didit does not have a fixed list of what we keep. Your compliance team configures each app in the Business Console, and the workflow only collects and stores what you tell it to.
The Returned-data tab gives you a toggle for every category:
- Identity (ID) document images and Machine-Readable Zone (MRZ) fields
- Near-Field Communication (NFC) chip data
- Extracted identity fields (name, date of birth, document number, expiry, address)
- Biometric templates
- Raw selfie and full liveness video
- Device fingerprint, browser, operating system, platform
- Internet Protocol (IP) geolocation, Virtual Private Network (VPN) / Tor signals
- Document-location match coordinates
- Anti-Money Laundering (AML) screening hits with sanctions, Politically Exposed Person (PEP), and adverse-media match details
- Webhook payload, audit log, and per-session metadata
The exact list of toggles depends on the modules in your workflow, check them when you set the workflow up in the Business Console under Returned-data.
Who is the Data Controller and who is the Data Processor?
You are the Data Controller. Didit is the Data Processor. This is the General Data Protection Regulation (GDPR) Article 28 set-up most regulated buyers expect.
- You decide why the data is collected, what fields are kept, how long they are retained, and who inside your team can act on them. The Data Processing Agreement (DPA) on this page is the contract that binds Didit to those instructions.
- Didit processes the data on your behalf, running the verifications, the screening, the biometric checks, the document classification, the webhooks, under your DPA and under our own SOC 2, ISO/IEC 27001, and General Data Protection Regulation (GDPR) Article 32 controls.
We recommend you let Didit store and access the data on your behalf. Most of our customers do. Securing identity data at internet scale is a full-time job: hardened encryption, key rotation, intrusion detection, vulnerability management, certification renewals, regional residency, data-subject-rights tooling, breach notification. Didit's security and platform teams focus on it every day so your compliance and engineering teams do not have to. You retain full control through the Business Console, every retention rule, every Data Subject Access Request (DSAR), every delete is yours to trigger.
If your policy requires the data to live entirely in your own environment (your cloud account, your on-premise database), we support that too, Didit runs as a processor on a fetch-and-forget basis and your team owns retention end to end.
Where is data stored, and can I choose the region?
European Union by default. Specific region or in-country available on Enterprise.
The default deployment runs on Amazon Web Services (AWS) in EU. Data is encrypted at rest and in transit, with encryption keys held by AWS and separated per environment.
- European Union (default), every account. Covers the General Data Protection Regulation (GDPR), Schrems II / European Union, United States Data Privacy Framework, and eIDAS 2.0.
- Specific region (United States East, Asia-Pacific, etc.), Enterprise contracts, when your regulator requires it.
- In-country residency (Brazil, India, etc.), Enterprise, subject to availability, for local laws like Brazil's Lei Geral de Proteção de Dados (LGPD) and India's Digital Personal Data Protection Act (DPDPA).
When data crosses a border, it is protected by the European Commission's 2021 Standard Contractual Clauses (SCCs). The matching Transfer Impact Assessment (TIA) ships with the Trust Pack on this page.
How long do you keep data, and how do I configure retention?
You set the retention window. From 1 month to 10 years, per app. Enforcement is automatic.
In the Business Console you set:
- A global retention window, anywhere from 1 month (when you want Didit to keep nothing after your webhook fires) to 10 years (the Anti-Money Laundering Directive 6 (AMLD6) ceiling).
- Per-data-category retention, biometric templates can outlive raw images; screening hits can outlive identity data; document-location match can be dropped entirely.
- Automatic enforcement, every night, the platform deletes anything past its retention window across every copy. Every delete is recorded in the audit log.
If you want Didit to keep nothing after the verdict, call POST /v3/sessions/:session_id/delete/ from your webhook handler and the session is gone the moment your system records its own copy of the result, Didit never holds the data past the call. Full reference at docs.didit.me/sessions-api/delete-session.
How do you handle Data Subject Access Requests (DSARs), deletion, and portability?
One endpoint per right.
- Right of access (Article 15) and right to data portability (Article 20), pull the full session payload at
GET /v3/sessions/:session_id/decision/. Reference atdocs.didit.me/sessions-api/retrieve-session. - Right to erasure (Article 17),
POST /v3/sessions/:session_id/delete/removes the session and every linked artifact. Reference atdocs.didit.me/sessions-api/delete-session.
Which certifications and attestations do you hold?
Five external attestations on file. All packaged in the Trust Pack.
- SOC 2 Type 1, Security, Availability, and Confidentiality, issued by ATOM in April 2026 under the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria. SOC 2 Type 2 examination is in progress.
- ISO/IEC 27001:2022, Information Security Management System, certified by Bureau Veritas (certificate
ES144068, valid through 2027-06-03). - iBeta Level 1 Presentation Attack Detection (PAD), independent biometric anti-spoofing test, conducted under ISO/IEC 30107-3 at a National Institute of Standards and Technology (NIST)-accredited lab. 0 successful attacks across 360 attempts.
- GDPR Article 32, Data Processing Agreement (DPA), sub-processor list, and Technical and Organisational Measures (TOMs), all public.
- European Banking Authority (EBA) / Markets in Crypto-Assets (MiCA) memo, independent legal opinion that Didit satisfies the EBA Guidelines on remote customer onboarding (
EBA/GL/2022/15) and the MiCA regulation.
Request the Trust Pack on this page and we send every report, certificate, and memo back the same business day under a signed Non-Disclosure Agreement (NDA).
What does the Spanish regulator attestation actually mean for me?
Mutual recognition across the European Union (EU), and a regulator-defensible audit trail.
Spain's Tesoro Público, Banco de España, SEPBLAC, and CNMV ran a year-long financial sandbox (November 2024 – July 2025) on Didit's Near-Field Communication (NFC) chip read plus active liveness onboarding flow. The official conclusions report, published on tesoro.es, finds Didit's remote verification meets or exceeds the security level of in-person identification under the Anti-Money Laundering Directive (AMLD).
For your compliance team this means:
- AMLD6 mutual recognition, the attestation is portable across every other EU member state without re-certification.
- eIDAS 2.0 alignment, Didit's NFC + liveness flow is on the public record as suitable for Qualified Electronic Signature (QES) onboarding.
- Defensible audit trail, when your local Financial Intelligence Unit (FIU) reviews your onboarding, you point at the same report your EU peer regulators have signed off on.
Didit is the only identity-verification vendor with this attestation on the public record.
Can I ask Didit to obtain a specific license or certification?
Yes, and we are probably already working on it. Didit is actively pursuing 10+ certifications, licenses, and regulator approvals across markets and verticals at any given time: payment authorisations, crypto and Markets in Crypto-Assets (MiCA) registrations, Anti-Money Laundering (AML) supervisor approvals, eIDAS 2.0 Qualified Trust Service Provider (QTSP) status, regional Financial Intelligence Unit (FIU) reporting, and vertical-specific authorisations (iGaming, healthcare, banking).
If there is a license or certification your compliance team needs Didit to hold, email `security@didit.me`. Odds are it is already in our queue, and if it is not, your request bumps it up the list. We come back with:
- Where the certification sits in our roadmap.
- The expected timeline.
- The scope (full coverage, a specific region, a specific module).