Legal / Compliance
Compliance
SOC 2
Status
BehalfID has not yet completed a SOC 2 Type II audit. We are currently implementing the organizational and technical controls required to achieve SOC 2 Type II certification across the Security, Availability, and Confidentiality trust service criteria.
Controls in place today
The following technical controls are implemented across all BehalfID environments:
- All data in transit encrypted with TLS 1.2+
- Webhook payloads signed with HMAC-SHA256; signatures verified before processing
- Audit trail of every permission decision (agent ID, action, outcome, timestamp)
- Rate limiting on all public endpoints to prevent abuse
Roadmap
We intend to engage a licensed CPA firm for a SOC 2 Type II audit once we have deployed the remaining organizational controls. Target: 2026.
ISO 27001
Status
BehalfID has not yet obtained ISO 27001 certification. The technical controls required by ISO 27001 Annex A are substantially implemented (see Technical Controls below). Formal certification requires a documented ISMS, risk register, and third-party audit.
HIPAA
Status
BehalfID is not currently HIPAA-certified. The service is not intended for use in workflows that process Protected Health Information (PHI) as defined by HIPAA.
If you are building a health-adjacent application and need to route verification decisions through BehalfID, contact us to discuss whether a Business Associate Agreement (BAA) is appropriate for your use case.
GDPR
Status
BehalfID processes personal data of EU/EEA residents where developers (data controllers) use the service. As a data processor, BehalfID:
- Processes personal data only as instructed by the controller (the developer using BehalfID).
- Does not transfer EU personal data outside the EEA/UK without appropriate safeguards.
- Provides data subject rights mechanisms (access, deletion, portability) via the developer portal and by request to legal@behalfid.com.
- Maintains a record of processing activities.
- Notifies affected controllers within 72 hours of discovering a data breach.
Developers using BehalfID who process EU personal data in verification calls (e.g., passing a user ID as metadata) should ensure they have the appropriate legal basis and that a Data Processing Agreement (DPA) is in place. Email legal@behalfid.com to request a DPA.
CCPA / CPRA
Status
BehalfID does not sell personal information of California residents. BehalfID does not use personal data collected through the service for advertising or cross-context behavioral tracking.
California residents have the right to:
- Know what personal information BehalfID collects and how it is used.
- Delete personal information held by BehalfID.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (BehalfID does not sell or share personal data).
To exercise these rights, email legal@behalfid.com.
Technical controls
The following technical controls are implemented across all BehalfID environments:
- All data in transit encrypted with TLS 1.2+
- API keys stored only as SHA-256 hashes — never in plaintext
- Developer passwords hashed with scrypt
- Session cookies are HTTP-only, SameSite-strict, and expire after 30 days of inactivity
- Webhook payloads signed with HMAC-SHA256; signatures verified before processing
- Verification logs retained for 90 days, webhook delivery records for 30 days
- Rate limiting on all public endpoints to prevent abuse
- Audit trail of every permission decision (agent ID, action, outcome, timestamp)
- IP addresses used only for rate limiting; not persisted or linked to accounts
- No third-party analytics, advertising trackers, or cross-site tracking scripts
Contact
For compliance questionnaires, Data Processing Agreements, or security questions, contact legal@behalfid.com or security@behalfid.com.