Trust
What we do with your data
An identity platform asks for more trust than most software. Here is what we can tell you plainly, and what we would rather you verified yourself than took our word for.
Your data stays where you put it
On our cloud you choose the region. Self-managed, nothing leaves your boundary at all — including the audit record. There is no telemetry route that carries your identity data back to us.
Tenants stay separate
Service providers can keep clients pooled for efficiency or fully separated where a client contract demands it — per client, not per platform.
Verify it without trusting us
The audit record is tamper-evident, and its integrity can be checked independently. A control you can only confirm by asking the vendor is not a control.
Tell us when we are wrong
We operate a responsible disclosure process and would rather hear it from a researcher than from a customer. Report something.
What we will not claim here
Certification status changes, and a marketing page is the wrong place to be imprecise about it. Ask us for our current certifications, audit reports and penetration test summaries and we will send the real documents — dated, and with the scope attached. If a vendor’s trust page tells you everything is fine without showing you the scope, that page is marketing.
Where we are still maturing
Our own security-posture scoring is self-attested today, and our key handling is an area we are still developing. Both are named in every executive briefing we give, and they are on the comparison page too. We would rather you heard it from us first.