Skip to main content
Behalf/ID
DocsBlogSecurityStatus
Sign inContinue with GoogleGet started
Get started

Legal / Compliance

Compliance

BehalfID is committed to strong security and privacy practices. This page documents our posture against the most common compliance frameworks and what controls are in place today. For questions or a compliance questionnaire, email legal@behalfid.com.

On this page

  1. SOC 2
  2. ISO 27001
  3. HIPAA
  4. GDPR
  5. CCPA / CPRA
  6. Technical controls
  7. Contact

SOC 2

Status

Certification in progress

BehalfID has not yet completed a SOC 2 Type II audit. We are currently implementing the organizational and technical controls required to achieve SOC 2 Type II certification across the Security, Availability, and Confidentiality trust service criteria.

Controls in place today

The following technical controls are implemented across all BehalfID environments:

  • All data in transit encrypted with TLS 1.2+
  • Webhook payloads signed with HMAC-SHA256; signatures verified before processing
  • Audit trail of every permission decision (agent ID, action, outcome, timestamp)
  • Rate limiting on all public endpoints to prevent abuse

Roadmap

We intend to engage a licensed CPA firm for a SOC 2 Type II audit once we have deployed the remaining organizational controls. Target: 2026.

ISO 27001

Status

Not certified

BehalfID has not yet obtained ISO 27001 certification. The technical controls required by ISO 27001 Annex A are substantially implemented (see Technical Controls below). Formal certification requires a documented ISMS, risk register, and third-party audit.

HIPAA

Status

Not applicable

BehalfID is not currently HIPAA-certified. The service is not intended for use in workflows that process Protected Health Information (PHI) as defined by HIPAA.

If you are building a health-adjacent application and need to route verification decisions through BehalfID, contact us to discuss whether a Business Associate Agreement (BAA) is appropriate for your use case.

GDPR

Status

Partial compliance

BehalfID processes personal data of EU/EEA residents where developers (data controllers) use the service. As a data processor, BehalfID:

  • Processes personal data only as instructed by the controller (the developer using BehalfID).
  • Does not transfer EU personal data outside the EEA/UK without appropriate safeguards.
  • Provides data subject rights mechanisms (access, deletion, portability) via the developer portal and by request to legal@behalfid.com.
  • Maintains a record of processing activities.
  • Notifies affected controllers within 72 hours of discovering a data breach.

Developers using BehalfID who process EU personal data in verification calls (e.g., passing a user ID as metadata) should ensure they have the appropriate legal basis and that a Data Processing Agreement (DPA) is in place. Email legal@behalfid.com to request a DPA.

CCPA / CPRA

Status

Implemented

BehalfID does not sell personal information of California residents. BehalfID does not use personal data collected through the service for advertising or cross-context behavioral tracking.

California residents have the right to:

  • Know what personal information BehalfID collects and how it is used.
  • Delete personal information held by BehalfID.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information (BehalfID does not sell or share personal data).

To exercise these rights, email legal@behalfid.com.

Technical controls

The following technical controls are implemented across all BehalfID environments:

  • All data in transit encrypted with TLS 1.2+
  • API keys stored only as SHA-256 hashes — never in plaintext
  • Developer passwords hashed with scrypt
  • Session cookies are HTTP-only, SameSite-strict, and expire after 30 days of inactivity
  • Webhook payloads signed with HMAC-SHA256; signatures verified before processing
  • Verification logs retained for 90 days, webhook delivery records for 30 days
  • Rate limiting on all public endpoints to prevent abuse
  • Audit trail of every permission decision (agent ID, action, outcome, timestamp)
  • IP addresses used only for rate limiting; not persisted or linked to accounts
  • No third-party analytics, advertising trackers, or cross-site tracking scripts

Contact

For compliance questionnaires, Data Processing Agreements, or security questions, contact legal@behalfid.com or security@behalfid.com.

Behalf/ID

Approval gates
for coding agents.

© 2026 BehalfID

All systems operational
CLISDK
Product
  • Sandbox
  • Design partners
  • Security
  • Blog
  • Start building
Docs
  • Quickstart
  • Deploy approvals
  • CLI & MCP
  • API reference
  • SDK
Company
  • Design system
  • Status
  • Design partners
Legal
  • Legal hub
  • Terms of Service
  • Privacy policy
  • Security
  • Compliance