Trust center

We sell proof.
Here's ours.

SOC 2 Type II operations. FIDO2-conformant authenticators. GDPR-aligned data handling. A 99.95% uptime SLA. The evidence is a request away.

What we hold

SOC 2

TYPE II

FIDO2

COMPLIANT

GDPR

ALIGNED

SLA

99.95%

ScrambleID is a FIDO Alliance member.

How we run security

Key custody

Server-side keys live in AWS KMS, in HSMs validated to FIPS 140-3 Security Level 3. Device-side keys are generated in the platform secure enclave and never leave it.

Penetration testing

Independent and continuous. Not an annual checkbox.

Incident response

Confirmed incidents: customers notified within 24 hours.

Get the evidence

SOC 2 report

Type II report, unqualified opinion, on request.

Questionnaires

CAIQ, SIG, or your own format. Send it.

DPA

Standard data processing agreement, available for review.

Responsible disclosure

Report vulnerabilities to security@scrambleid.com.

Next step

Ask us the hard questions.
That's the point.

Bring your vendor-risk review. We'll answer it like a security team, not a sales team.