COMPLIANCE & TRUST

Trust Centre

Transparency, security, and compliance at the core of everything we build.

Security & Privacy

At Affinidi, we build privacy-first infrastructure that puts users in control of their data. Our commitment to security and privacy is reflected in our open standards approach and transparent operations.

SOC 2 Type II Certified

Independently audited and certified for security, availability, and confidentiality controls.

GDPR compliant

Full compliance with EU General Data Protection Regulation. Privacy by design and default.

ISO 27001 Certified

Information security management system certified to international standards.

CCPA compliant

California Consumer Privacy Act compliance ensuring user data rights and transparency.

Open standards & interoperability

We build on open standards to ensure interoperability, transparency, and no vendor lock-in.

W3C Verifiable Credentials

Standard for expressing credentials on the web in a secure, privacy-respecting manner.

Learn more →

W3C Decentralized Identifiers (DIDs)

Globally unique identifiers that enable verifiable, decentralised digital identity.

Learn more →

OpenID for verifiable credentials (OID4VC)

Protocol for issuing and presenting verifiable credentials using OpenID Connect.

Learn more →

DIDComm

Secure, private messaging protocol for decentralised identity interactions.

Learn more →

Security Practices

Continuous Monitoring

24/7 security monitoring and threat detection across all infrastructure.

Regular Audits

Third-party security audits and penetration testing on a regular basis.

Encryption at Rest & in Transit

All data encrypted using industry-standard protocols (TLS 1.3, AES-256).

Access Controls

Role-based access control (RBAC) and principle of least privilege across systems.

Incident Response

Documented incident response procedures with defined escalation paths.

Security Training

Regular security awareness training for all team members.

Transparency & Accountability

Open Source Components

Our core libraries and SDKs are open source, allowing community review and contribution.

View Open Source Projects →

Public Documentation

Comprehensive, publicly accessible documentation for all APIs, protocols, and integration patterns.

Read Documentation →

Responsible Disclosure

We welcome responsible disclosure of security vulnerabilities. Contact our security team directly.

security@affinidi.com →

Questions About Compliance?

Our compliance and security team is here to help answer any questions about our certifications, security practices, or data handling procedures.

Cookie Preferences

We use cookies to enhance your experience. You can manage your preferences below. For more information, read our Cookie Policy.

Strictly Necessary Always Active

These cookies are essential for core website functions such as security, session integrity, and cookie preference storage. They cannot be disabled.

  • _cf_bm: Distinguishes humans from bots (Cloudflare) · 30m
  • _cfuvid: Ensures secure browsing (Cloudflare) · Session
  • __hs_initial_opt_in: Prevents HubSpot's banner · 7 days
  • _gtm_debug: GTM debug mode (testing only) · Session
Analytics

These cookies help us understand how visitors interact with the site so we can improve content and performance. All data is aggregated and anonymous.

  • _ga, _gid, _gat: Google Analytics · Session – 2 years
  • __hstc, hubspotutk, __hssrc: HubSpot visitor tracking · 13 months
  • __hs_opt_out: HubSpot opt-out preference · 6 months
Marketing & Targeting

These cookies allow us and our partners to serve personalised ads and measure campaign performance.

  • _gcl_au, _gcl_dc: Google Ads conversion tracking · 90 days
  • IDE: Google Display Network personalisation · 1 year
  • _fbp: Meta / Facebook remarketing · 90 days
  • li_gc, _li_fat_id, bcookie: LinkedIn tracking · 1–24 months
  • guest_id, personalization_id: Twitter/X analytics · 2 years