VeridentiDocs
ChangelogFor BusinessContact
Docs Admin guide Compliance

Compliance

Where Veridenti stands on the frameworks enterprises ask about. We state this plainly and don't overclaim.

Current status

FrameworkStatus
SOC 2Readiness in progress (Type I targeted first)
ISO 27001Planned (on roadmap)
GDPR / CCPAAligned data handling; DPA available at contracting (counsel-approved)
HIPAAZero-knowledge architecture; BAA in preparation
21 CFR Part 11 / Annex 11Supported via the tamper-evident, hash-chained audit log

Data residency & sovereignty

Encrypted vault data can be pinned to a region (fail-closed). For strict sovereign regimes, Veridenti can target a sovereign provider, and the zero-knowledge design means a foreign legal request yields only undecryptable ciphertext. See Data residency.

Audit evidence

The tamper-evident audit log and Access reviews produce the recertification and activity evidence auditors expect, exportable on demand.

NoteFor your current certification status, a DPA, or a security questionnaire, contact your account team — we'll turn these around quickly.

What if…

Last updated August 26, 2026 · Docs v1.3
Enter to open · Esc to close
Veridenti