Apidentityby Adesio

Documents

Including the ones that do not exist. An absence stated is worth more than an absence you have to infer.

The verification standard Public What is checked, what each outcome means, and what the engine refuses to conclude.
Subprocessor list Public Generated from the same registry the engine enforces, so it cannot drift.
Data processing agreement On request Our standard DPA, for customers and prospects.
Records of processing (GDPR Art. 30) On request What is processed, why, on what basis, and for how long.
SOC 2 Type II report Does not exist yet No audit period has begun, so there is no report to withhold. When there is one it will be available to customers under NDA, and this line will say so.
Penetration test report Does not exist yet No third-party test has been commissioned. Stated because its absence is the answer.

Asking for one

Email bertier@ades.io with the document and who is asking. There is no form here on purpose: a request form that routes into a queue nobody has staffed is worse than an address that reaches a person.

If you are doing vendor due diligence on us

The honest summary is that Apidentity is early. There is no SOC 2 report and no penetration test, and this page says so rather than implying a maturity we have not reached. What there is instead is on the controls page: mechanisms you can name, each with the test that fails if it stops being true.

If that is not enough for your process, it should not be. Say so and we will tell you when it changes.