Founding-partner program now open · request a scoped proof →
Trust & compliance

Built for environments that cannot afford to guess.

This page covers our compliance posture, data handling, encryption model, subprocessors, and responsible disclosure — written for procurement teams, security reviewers, and InfoSec leads doing real due diligence.

What data we handle

Your identity data stays in your environment.

✓ What stays in your environment

  • Identity event payloads (who, what, when)
  • Pre-state and post-state of target systems
  • Evidence packs (written to your own S3 bucket)
  • Encryption keys (BYO-KMS, customer-held)
  • All connector credentials and API tokens

What reaches the SidentiQ control plane

  • Policy evaluation requests (anonymized by default)
  • Connector health telemetry
  • Execution status signals
No raw identity data, by default configuration.
Encryption & key ownership

The proof is yours — cryptographically.

In transit

Mutual TLS (mTLS) on all connector traffic. Certificate pinning available for regulated deployments.

At rest

Evidence packs signed with ECDSA P-256, hash-chained with SHA-256. S3 Object Lock in Compliance Mode.

Key ownership

BYO-KMS: you supply and rotate your own KMS key. SidentiQ cannot read evidence without your key access.

Compliance posture

Honest status. No green-check theater.

FrameworkStatusNotes
SOC 2 Type IIIn preparationControls designed to SOC 2 Trust Service Criteria. Formal audit engagement planned Q3 2026.
FedRAMPNot authorizedArchitecture informed by FedRAMP controls. Not authorized and does not claim authorization. Do not use for FedRAMP-in-scope workloads without independent review.
NIST 800-53 Rev.5Designed-toAC, AU, IA, and SI control families inform product design. Formal control mapping in progress; not independently assessed.
HIPAAAlignedDeployment patterns support HIPAA-aligned environments. BAA terms available for qualified deployments under signed agreement.
OWASP ASIAlignedAI-agent governance controls aligned to the OWASP Agentic Security Initiative guidelines.
Compliance references describe alignment and readiness, not certification, unless stated in a signed customer artifact.
Subprocessors

A short, honest list.

ProcessorPurposeData involved
Amazon Web ServicesControl-plane hosting, evidence storageCustomer-defined; evidence packs in customer-owned S3
CloudflareCDN and DDoS protection for public sitePublic web traffic only — no identity data
Responsible disclosure

Found something? Tell us.

If you discover a security issue, email [email protected] with a description, reproduction steps, and your contact details. We acknowledge within 2 business days and respond substantively within 10. Please allow reasonable time to investigate before public disclosure.

Evidence retention is customer-controlled. SidentiQ does not set or enforce retention periods — you configure S3 Object Lock and bucket lifecycle policies in your own AWS account.

Doing a security review?

We're happy to walk your team through the architecture, share control documentation, and discuss NDA evaluation terms.