Trust

What we do with your data

An identity platform asks for more trust than most software. Here is what we can tell you plainly, and what we would rather you verified yourself than took our word for.

RESIDENCY

Your data stays where you put it

On our cloud you choose the region. Self-managed, nothing leaves your boundary at all — including the audit record. There is no telemetry route that carries your identity data back to us.

SEPARATION

Tenants stay separate

Service providers can keep clients pooled for efficiency or fully separated where a client contract demands it — per client, not per platform.

EVIDENCE

Verify it without trusting us

The audit record is tamper-evident, and its integrity can be checked independently. A control you can only confirm by asking the vendor is not a control.

DISCLOSURE

Tell us when we are wrong

We operate a responsible disclosure process and would rather hear it from a researcher than from a customer. Report something.

What we will not claim here

Certification status changes, and a marketing page is the wrong place to be imprecise about it. Ask us for our current certifications, audit reports and penetration test summaries and we will send the real documents — dated, and with the scope attached. If a vendor’s trust page tells you everything is fine without showing you the scope, that page is marketing.

Where we are still maturing

Our own security-posture scoring is self-attested today, and our key handling is an area we are still developing. Both are named in every executive briefing we give, and they are on the comparison page too. We would rather you heard it from us first.