NewSOC 2 Aina ya 1
Ukaguzi huru wa udhibiti wetu wa usalama, upatikanaji, na usiri, uliotolewa na ATOM mnamo Aprili 2026. Ukaguzi wa Aina ya 2 unaendelea.
Tunashughulikia leseni, kampuni tanzu, na ukaguzi ili timu yako ya kufuata sheria na hatari iweze kusonga haraka. Washa swichi na uzindue katika nchi yoyote kwa kufuata sheria, SOC 2 Type 1, ISO/IEC 27001, na uthibitisho wa serikali ya Tesoro EU zimejumuishwa.
“Uthibitishaji wa NFC + uhai hai wa Didit unatoa usalama sawa au mkubwa kuliko uthibitishaji wa ana kwa ana.”
Novemba 2024, Julai 2025 · Sandbox financiero (Sheria 7/2020), kundi la 4 · inasimamiwa na Tesoro Público, Banco de España, SEPBLAC, na CNMV.
Liveness, deepfake detection, document classifiers, face match, injection-attack detection, behavioural risk, kila model huishi katika mfumo wetu wa mafunzo na utoaji huduma.
Traffic ya uzalishaji hulisha foleni ya ukaguzi wa wakati halisi. Drift, false-positive rate, mabadiliko ya attack-pattern na ubora wa signal kwa kila nchi hufuatiliwa mfululizo; vizingiti hurekebishwa upya bila mabadiliko ya code ya mteja.
Kila model huunganishwa inline kwenye session. Sub-2-second p99 inference, hakuna round-trip ya ziada, hakuna tap ya ziada. Mtumiaji halali humaliza uthibitishaji katika flow ileile; mshambuliaji pekee ndiye huona njia tofauti.
NewUkaguzi huru wa udhibiti wetu wa usalama, upatikanaji, na usiri, uliotolewa na ATOM mnamo Aprili 2026. Ukaguzi wa Aina ya 2 unaendelea.

Inathibitisha kuwa usimamizi wetu wa usalama wa habari unashughulikia uthibitishaji wa Didit kuanzia mwanzo hadi mwisho. Imetolewa na Bureau Veritas, halali hadi Juni 2027.

Jaribio la kuzuia udanganyifu wa kibayometriki, majaribio 360 katika kategoria sita za mashambulizi, hakuna hata moja iliyopita. Ilifanywa katika maabara ya NVLAP iliyoidhinishwa na NIST 200962.
Sandbox ya mwaka mzima iliyofanywa na wadhibiti wanne wa kifedha wa Uhispania ilihitimisha kuwa uthibitishaji wa mbali wa Didit ni salama angalau kama ukaguzi wa vitambulisho vya ana kwa ana. Hakuna mtoa huduma mwingine wa utambulisho anayeshikilia hii.

Uzingatiaji kamili wa Kanuni Kuu ya Ulinzi wa Data (GDPR) kama Mchakataji Data. Mkataba wa Uchakataji Data na Hatua za Kiufundi na Kiutendaji zinapatikana kwa ombi.

Maoni huru ya kisheria: Usajili wa mbali wa Didit unakidhi Miongozo ya Mamlaka ya Benki ya Ulaya kuhusu usajili wa wateja wa mbali (EBA/GL/2022/15) na inaoana na Kitabu cha Kanuni Moja cha Kupambana na Utakatishaji Fedha (AML) cha EU na kanuni ya Masoko katika Mali za Crypto (MiCA).
Kila kipindi kimesimbwa fiche kikiwa kimepumzika kwa funguo za AES (Advanced Encryption Standard) za biti 256. Funguo hazigusi kamwe msimbo wetu wa programu, zinakaa kwenye AWS KMS (Key Management Service), zikiwa na funguo tofauti kwa sandbox na production.
Kila API call, webhook, na kipindi cha Business Console kimesimbwa fiche kupitia TLS (Transport Layer Security) 1.3 kwa sheria kali za cipher. Itifaki za zamani haziwezi kurudi nyuma; HSTS (HTTP Strict Transport Security) inatekelezwa kwenye tovuti nzima.
Vipindi vinachakatwa na kuhifadhiwa katika Umoja wa Ulaya kwa chaguo-msingi kwenye AWS. Biashara inaweza kuwezesha makazi ndani ya nchi, kulingana na upatikanaji, ili timu katika soko lolote ziendeshe Didit kwa kufuata sheria.
Chagua muda ambao Didit huhifadhi kila kipindi, kutoka mwezi mmoja hadi miaka kumi, kwa kila programu kwenye Business Console. Usambazaji wa alama ndogo unaweza kufuta kipindi mara tu webhook inapoingia.
Unachagua ni data gani hasa Didit inakusanya, kila kitu kingine huachwa. Kwa chaguo-msingi, ni templates za biometriska na metadata pekee zinazohifadhiwa; selfies halisi na video ya uhai hufutwa mara tu kipindi kinapofungwa.
DSAR kamili (Ombi la Ufikiaji wa Data ya Mhusika) na haki ya kufutwa kwa ombi kupitia API ya umma. Watumiaji wa mwisho hutuma DSARs kutoka programu ya Didit Identity; timu yako huyaanzisha kwa DELETE call moja kwenye sessions endpoint. Inatekelezwa kwenye kila replica, hakuna soft-delete, hakuna archive bucket.
Zero data breaches since Didit launched in 2023. Security is built into every layer of the platform.
status.didit.me, every incident, every post-mortem, no login required. 100% uptime over the last 6 months.Request the Trust Pack on this page, SOC 2 report, ISO certificate, iBeta report, Tesoro attestation, Data Processing Agreement (DPA), sub-processors list, sent back the same business day under a signed Non-Disclosure Agreement (NDA).
Yes. The infrastructure scales itself in real time and supports millions of verifications a day.
status.didit.me, no login required.Volume tiers on the pricing page kick in automatically as you grow, no contract change, no manual renegotiation.
You choose, per workflow. Didit does not have a fixed list of what we keep. Your compliance team configures each app in the Business Console, and the workflow only collects and stores what you tell it to.
The Returned-data tab gives you a toggle for every category:
The exact list of toggles depends on the modules in your workflow, check them when you set the workflow up in the Business Console under Returned-data.
You are the Data Controller. Didit is the Data Processor. This is the General Data Protection Regulation (GDPR) Article 28 set-up most regulated buyers expect.
We recommend you let Didit store and access the data on your behalf. Most of our customers do. Securing identity data at internet scale is a full-time job: hardened encryption, key rotation, intrusion detection, vulnerability management, certification renewals, regional residency, data-subject-rights tooling, breach notification. Didit's security and platform teams focus on it every day so your compliance and engineering teams do not have to. You retain full control through the Business Console, every retention rule, every Data Subject Access Request (DSAR), every delete is yours to trigger.
If your policy requires the data to live entirely in your own environment (your cloud account, your on-premise database), we support that too, Didit runs as a processor on a fetch-and-forget basis and your team owns retention end to end.
European Union by default. Specific region or in-country available on Enterprise.
The default deployment runs on Amazon Web Services (AWS) in EU. Data is encrypted at rest and in transit, with encryption keys held by AWS and separated per environment.
When data crosses a border, it is protected by the European Commission's 2021 Standard Contractual Clauses (SCCs). The matching Transfer Impact Assessment (TIA) ships with the Trust Pack on this page.
You set the retention window. From 1 month to 10 years, per app. Enforcement is automatic.
In the Business Console you set:
If you want Didit to keep nothing after the verdict, call POST /v3/sessions/:session_id/delete/ from your webhook handler and the session is gone the moment your system records its own copy of the result, Didit never holds the data past the call. Full reference at docs.didit.me/sessions-api/delete-session.
One endpoint per right.
GET /v3/sessions/:session_id/decision/. Reference at docs.didit.me/sessions-api/retrieve-session.POST /v3/sessions/:session_id/delete/ removes the session and every linked artifact. Reference at docs.didit.me/sessions-api/delete-session.Five external attestations on file. All packaged in the Trust Pack.
ES144068, valid through 2027-06-03).EBA/GL/2022/15) and the MiCA regulation.Request the Trust Pack on this page and we send every report, certificate, and memo back the same business day under a signed Non-Disclosure Agreement (NDA).
Mutual recognition across the European Union (EU), and a regulator-defensible audit trail.
Spain's Tesoro Público, Banco de España, SEPBLAC, and CNMV ran a year-long financial sandbox (November 2024 – July 2025) on Didit's Near-Field Communication (NFC) chip read plus active liveness onboarding flow. The official conclusions report, published on tesoro.es, finds Didit's remote verification meets or exceeds the security level of in-person identification under the Anti-Money Laundering Directive (AMLD).
For your compliance team this means:
Didit is the only identity-verification vendor with this attestation on the public record.
Yes, and we are probably already working on it. Didit is actively pursuing 10+ certifications, licenses, and regulator approvals across markets and verticals at any given time: payment authorisations, crypto and Markets in Crypto-Assets (MiCA) registrations, Anti-Money Laundering (AML) supervisor approvals, eIDAS 2.0 Qualified Trust Service Provider (QTSP) status, regional Financial Intelligence Unit (FIU) reporting, and vertical-specific authorisations (iGaming, healthcare, banking).
If there is a license or certification your compliance team needs Didit to hold, email `security@didit.me`. Odds are it is already in our queue, and if it is not, your request bumps it up the list. We come back with:
API moja kwa KYC, KYB, Ufuatiliaji wa Miamala, na Uchunguzi wa Wallet. Unganisha ndani ya dakika 5.