Skip to main content
Didit 融资 750 万美元,打造身份与欺诈基础设施
Didit
信任

我们承担合规重任,助您 一键

我们负责处理许可证、子公司和审计,让您的合规和风控团队能够更快行动。一键切换,即可在任何国家合规上线, 包括 SOC 2 Type 1、ISO/IEC 27001 和 Tesoro 欧盟政府认证。

数据一览

数据一览
  • 0%
    过去 12 个月的实际正常运行时间。在 status.didit.me 上实时记录,符合 99.99% SLO (Service Level Objective)。
  • 0
    Didit 推出以来无重大安全漏洞。自 2023 年起在生产环境中久经考验。
  • 数百万
    每月在生产集群上验证的用户数量。
  • 已认证
    Didit 运营所在地的所有区域均符合合规要求, SOC 2 Type 1、ISO/IEC 27001、iBeta Level 1 PAD 和西班牙监管机构认证。
公开记录

监管机构称 Didit 比线下验证更安全。

西班牙对 Didit 的远程近场通信 (NFC) 芯片读取和主动活体检测进行了压力测试,并公开记录其安全性至少与线下身份验证相当。没有其他身份提供商获得此认证。
受以下机构监管
  • Tesoro Público, 西班牙财政部
  • Banco de España, 西班牙银行
  • SEPBLAC, 西班牙金融情报机构
  • CNMV, 西班牙国家证券市场委员会
Didit 的 NFC + 主动活体验证提供的安全性等同或高于线下验证。
西班牙财政部, Informe de Conclusiones DIDIT,2026 年 2 月

2024 年 11 月, 2025 年 7 月 · 金融沙盒 (Ley 7/2020),第四批 · 由 Tesoro Público、西班牙银行、SEPBLAC 和 CNMV 监管。

欺诈工程

专业的欺诈团队。 模型、监控、预防。

一个专注于欺诈的团队构建、训练和监控每个 Didit 会话背后的检测模型, 包括深度伪造、注入攻击、伪造、合成身份、洗钱骡子。野外出现新攻击?本周就会有新信号。合法用户永远不会察觉。
  • 模型, 内部构建与再训练。

    活体检测、深度伪造检测、文档分类器、人脸匹配、注入攻击检测、行为风险, 所有模型都在我们自己的训练和服务管道中运行。

  • 监控, 每时每刻,每个会话。

    生产流量实时进入审查队列。漂移、误报率、攻击模式变化和各国信号质量持续受到监控;阈值无需客户代码更改即可重新调整。

  • 预防, 内联,用户无感知。

    每个模型都在会话中内联集成。p99 推理时间低于 2 秒,无需额外往返,无需额外操作。合法用户在同一流程中完成验证;只有攻击者会看到不同的路径。

认证

每项声明都有文件支持。

六项外部认证涵盖安全性、隐私、生物识别防欺骗、监管合规性和政府认可。每张卡片都提供真实文件,而非营销 PDF。
SOC 2 Type 1 认证徽章New
AICPA · 2026-04-09

SOC 2 Type 1

由 ATOM 于 2026 年 4 月发布的,对我们安全性、可用性和保密性控制的独立审计。Type 2 审查正在进行中。

Bureau Veritas 颁发的 ISO 27001 证书
ES144068 · Bureau Veritas

ISO/IEC 27001:2022

证明我们的信息安全管理涵盖 Didit 验证的端到端流程。由 Bureau Veritas 颁发,有效期至 2027 年 6 月。

iBeta Level 1 PAD 合规徽章
ISO/IEC 30107-3 · NIST/NVLAP

iBeta Level 1 PAD

生物识别防欺骗测试, 六类攻击共 360 次尝试,无一成功。在 NIST 认可的 NVLAP 实验室 200962 进行。

Tesoro Público, 西班牙财政部标志
西班牙 · CNMV · SEPBLAC · BdE

Tesoro 沙盒认证

西班牙四家金融监管机构为期一年的沙盒测试得出结论:Didit 的远程验证至少与现场身份检查一样安全。其他身份验证供应商均未获得此认证。

GDPR 就绪徽章
EU 2016/679 · DPA · TOMs

GDPR 第 32 条

作为数据处理者,完全符合通用数据保护条例 (GDPR)。可应要求提供数据处理协议以及技术和组织措施。

EBA / MiCA 合规徽章
EBA/GL/2022/15 · MiCA

EBA / MiCA 合规性

独立法律意见:Didit 的远程入驻符合欧洲银行管理局关于远程客户入驻的指南 (EBA/GL/2022/15),并与即将生效的欧盟反洗钱 (AML) 单一规则手册和加密资产市场 (MiCA) 法规兼容。

数据保护

我们存储什么、存储在哪里、存储多久。

您拥有数据;Didit 代表您处理数据。根据 GDPR(通用数据保护条例),您是数据控制者,Didit 是数据处理者。平台内置 GDPR 第 32 条控制和本地数据保护规则。
  • 静态加密AES-256.

    每个会话都使用 256 位 AES(高级加密标准)密钥进行静态加密。密钥不会接触我们的应用程序代码,它们存储在 AWS KMS(密钥管理服务)中,沙盒和生产环境使用不同的密钥。

  • 传输加密TLS 1.3.

    每个 API 调用、Webhook 和业务控制台会话都通过 TLS(传输层安全)1.3 进行加密,并采用严格的密码规则。旧协议无法回退;HSTS(HTTP 严格传输安全)在全站强制执行。

  • 数据驻留默认欧盟.

    会话默认在 AWS 上的欧盟地区进行处理和存储。企业可以启用国家内驻留,具体取决于可用性, 因此任何市场的团队都可以合规地运行 Didit。

  • 数据保留1 个月到 10 年.

    在业务控制台中,您可以为每个应用程序选择 Didit 保留每个会话的时长, 从一个月到十年。最小化部署可以在 Webhook 到达后立即删除会话。

  • 生物识别处理数据最小化.

    您精确选择 Didit 收集哪些数据, 其他所有数据都将被丢弃。默认情况下,只保留生物识别模板和元数据;原始自拍和活体视频在会话关闭时立即删除。

  • 数据主体权利通过一个端点删除数据.

    通过公共 API 按需提供完整的 DSAR(数据主体访问请求)和删除权。终端用户从 Didit Identity 应用程序发送 DSAR;您的团队通过对会话端点进行一次 DELETE 调用来触发它们。在每个副本上强制执行, 无软删除,无归档存储桶。

FAQ

安全问题,已解答。

我们发送给企业安全团队的相同答案。其他问题请发送至 security@didit.me。
How secure is Didit?

Zero data breaches since Didit launched in 2023. Security is built into every layer of the platform.

  • Zero breaches, across millions of verifications and 1,500+ paying customers.
  • Everything is encrypted, both when data is stored and when it moves between systems. Encryption keys live in Amazon Web Services (AWS), separated so a sandbox cannot read production data.
  • Every request is checked. Every action is logged. No shared secrets across customers.
  • Independently audited, SOC 2 Type 1 (Type 2 in progress), ISO/IEC 27001:2022, and iBeta Level 1 Presentation Attack Detection (PAD) with 0% attack-success across 360 attempts.
  • Live public status page at status.didit.me, every incident, every post-mortem, no login required. 100% uptime over the last 6 months.
  • If anything happens, we tell you within hours, well inside the General Data Protection Regulation (GDPR) Article 33 reporting window. Enterprise gets a named engineer on call 24/7, with a dedicated Slack and WhatsApp channel.

Request the Trust Pack on this page, SOC 2 report, ISO certificate, iBeta report, Tesoro attestation, Data Processing Agreement (DPA), sub-processors list, sent back the same business day under a signed Non-Disclosure Agreement (NDA).

I have lots of verifications. Will Didit support my volume?

Yes. The infrastructure scales itself in real time and supports millions of verifications a day.

  • Scales automatically. When your traffic doubles overnight, the platform expands itself. No sales call, no capacity-plan rewrite, no warning needed.
  • Every check completes in under 2 seconds, even at peak load. The infrastructure is optimised for fast inference end to end.
  • 100% uptime over the last 6 months. Track it live at status.didit.me, no login required.
  • Battle-tested in production, 1,500+ paying customers across 220+ countries, in production since 2023.
  • Built for spike events, sports-betting kick-offs, marketplace launches, age-verification rollouts. The platform handles the spike without anyone at Didit having to lift a finger.
  • Enterprise contracts include written guarantees, a Service Level Agreement (SLA) on speed, uptime, and capacity, with billing credits if we miss.

Volume tiers on the pricing page kick in automatically as you grow, no contract change, no manual renegotiation.

What data does Didit store, and how much control do I have over it?

You choose, per workflow. Didit does not have a fixed list of what we keep. Your compliance team configures each app in the Business Console, and the workflow only collects and stores what you tell it to.

The Returned-data tab gives you a toggle for every category:

  • Identity (ID) document images and Machine-Readable Zone (MRZ) fields
  • Near-Field Communication (NFC) chip data
  • Extracted identity fields (name, date of birth, document number, expiry, address)
  • Biometric templates
  • Raw selfie and full liveness video
  • Device fingerprint, browser, operating system, platform
  • Internet Protocol (IP) geolocation, Virtual Private Network (VPN) / Tor signals
  • Document-location match coordinates
  • Anti-Money Laundering (AML) screening hits with sanctions, Politically Exposed Person (PEP), and adverse-media match details
  • Webhook payload, audit log, and per-session metadata

The exact list of toggles depends on the modules in your workflow, check them when you set the workflow up in the Business Console under Returned-data.

Who is the Data Controller and who is the Data Processor?

You are the Data Controller. Didit is the Data Processor. This is the General Data Protection Regulation (GDPR) Article 28 set-up most regulated buyers expect.

  • You decide why the data is collected, what fields are kept, how long they are retained, and who inside your team can act on them. The Data Processing Agreement (DPA) on this page is the contract that binds Didit to those instructions.
  • Didit processes the data on your behalf, running the verifications, the screening, the biometric checks, the document classification, the webhooks, under your DPA and under our own SOC 2, ISO/IEC 27001, and General Data Protection Regulation (GDPR) Article 32 controls.

We recommend you let Didit store and access the data on your behalf. Most of our customers do. Securing identity data at internet scale is a full-time job: hardened encryption, key rotation, intrusion detection, vulnerability management, certification renewals, regional residency, data-subject-rights tooling, breach notification. Didit's security and platform teams focus on it every day so your compliance and engineering teams do not have to. You retain full control through the Business Console, every retention rule, every Data Subject Access Request (DSAR), every delete is yours to trigger.

If your policy requires the data to live entirely in your own environment (your cloud account, your on-premise database), we support that too, Didit runs as a processor on a fetch-and-forget basis and your team owns retention end to end.

Where is data stored, and can I choose the region?

European Union by default. Specific region or in-country available on Enterprise.

The default deployment runs on Amazon Web Services (AWS) in EU. Data is encrypted at rest and in transit, with encryption keys held by AWS and separated per environment.

  • European Union (default), every account. Covers the General Data Protection Regulation (GDPR), Schrems II / European Union, United States Data Privacy Framework, and eIDAS 2.0.
  • Specific region (United States East, Asia-Pacific, etc.), Enterprise contracts, when your regulator requires it.
  • In-country residency (Brazil, India, etc.), Enterprise, subject to availability, for local laws like Brazil's Lei Geral de Proteção de Dados (LGPD) and India's Digital Personal Data Protection Act (DPDPA).

When data crosses a border, it is protected by the European Commission's 2021 Standard Contractual Clauses (SCCs). The matching Transfer Impact Assessment (TIA) ships with the Trust Pack on this page.

How long do you keep data, and how do I configure retention?

You set the retention window. From 1 month to 10 years, per app. Enforcement is automatic.

In the Business Console you set:

  • A global retention window, anywhere from 1 month (when you want Didit to keep nothing after your webhook fires) to 10 years (the Anti-Money Laundering Directive 6 (AMLD6) ceiling).
  • Per-data-category retention, biometric templates can outlive raw images; screening hits can outlive identity data; document-location match can be dropped entirely.
  • Automatic enforcement, every night, the platform deletes anything past its retention window across every copy. Every delete is recorded in the audit log.

If you want Didit to keep nothing after the verdict, call POST /v3/sessions/:session_id/delete/ from your webhook handler and the session is gone the moment your system records its own copy of the result, Didit never holds the data past the call. Full reference at docs.didit.me/sessions-api/delete-session.

How do you handle Data Subject Access Requests (DSARs), deletion, and portability?

One endpoint per right.

  • Right of access (Article 15) and right to data portability (Article 20), pull the full session payload at GET /v3/sessions/:session_id/decision/. Reference at docs.didit.me/sessions-api/retrieve-session.
  • Right to erasure (Article 17), POST /v3/sessions/:session_id/delete/ removes the session and every linked artifact. Reference at docs.didit.me/sessions-api/delete-session.
Which certifications and attestations do you hold?

Five external attestations on file. All packaged in the Trust Pack.

  • SOC 2 Type 1, Security, Availability, and Confidentiality, issued by ATOM in April 2026 under the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria. SOC 2 Type 2 examination is in progress.
  • ISO/IEC 27001:2022, Information Security Management System, certified by Bureau Veritas (certificate ES144068, valid through 2027-06-03).
  • iBeta Level 1 Presentation Attack Detection (PAD), independent biometric anti-spoofing test, conducted under ISO/IEC 30107-3 at a National Institute of Standards and Technology (NIST)-accredited lab. 0 successful attacks across 360 attempts.
  • GDPR Article 32, Data Processing Agreement (DPA), sub-processor list, and Technical and Organisational Measures (TOMs), all public.
  • European Banking Authority (EBA) / Markets in Crypto-Assets (MiCA) memo, independent legal opinion that Didit satisfies the EBA Guidelines on remote customer onboarding (EBA/GL/2022/15) and the MiCA regulation.

Request the Trust Pack on this page and we send every report, certificate, and memo back the same business day under a signed Non-Disclosure Agreement (NDA).

What does the Spanish regulator attestation actually mean for me?

Mutual recognition across the European Union (EU), and a regulator-defensible audit trail.

Spain's Tesoro Público, Banco de España, SEPBLAC, and CNMV ran a year-long financial sandbox (November 2024 – July 2025) on Didit's Near-Field Communication (NFC) chip read plus active liveness onboarding flow. The official conclusions report, published on tesoro.es, finds Didit's remote verification meets or exceeds the security level of in-person identification under the Anti-Money Laundering Directive (AMLD).

For your compliance team this means:

  • AMLD6 mutual recognition, the attestation is portable across every other EU member state without re-certification.
  • eIDAS 2.0 alignment, Didit's NFC + liveness flow is on the public record as suitable for Qualified Electronic Signature (QES) onboarding.
  • Defensible audit trail, when your local Financial Intelligence Unit (FIU) reviews your onboarding, you point at the same report your EU peer regulators have signed off on.

Didit is the only identity-verification vendor with this attestation on the public record.

Can I ask Didit to obtain a specific license or certification?

Yes, and we are probably already working on it. Didit is actively pursuing 10+ certifications, licenses, and regulator approvals across markets and verticals at any given time: payment authorisations, crypto and Markets in Crypto-Assets (MiCA) registrations, Anti-Money Laundering (AML) supervisor approvals, eIDAS 2.0 Qualified Trust Service Provider (QTSP) status, regional Financial Intelligence Unit (FIU) reporting, and vertical-specific authorisations (iGaming, healthcare, banking).

If there is a license or certification your compliance team needs Didit to hold, email `security@didit.me`. Odds are it is already in our queue, and if it is not, your request bumps it up the list. We come back with:

  • Where the certification sits in our roadmap.
  • The expected timeline.
  • The scope (full coverage, a specific region, a specific module).

身份与欺诈基础设施。

一个 API 即可实现 KYC、KYB、交易监控和钱包筛选。5 分钟即可集成。

让 AI 总结此页面