Apidentityby Adesio

Trust centre

What we hold, what we do not, and what enforces the difference. Every control below names the migration, grant or test that makes it true — because a trust centre kept by hand drifts, and a drifted one is worse than none.

The short version

No subprocessor holds any of your data. Screening runs against lists we download and match in process, so the name of the company you are checking is never sent anywhere. Declarant identity is established by a qualified trust service under eIDAS, so no biometric data is processed here at all.

Hosted in the European Union. Evidence is immutable and the audit log is hash-chained, so a removed or altered record is detectable rather than merely discouraged.

Where we stand on frameworks

SOC 2 Type II Intended, not started Scoped to Security, Confidentiality, Availability and Processing Integrity. The last of those is unusual and deliberate: "outputs are complete, accurate, timely and authorised" is literally what a verification engine sells, and most vendors leave it out. No audit period has begun and no report exists.
ISO 27001 Not held Not held, not in progress. A previous generation of this product stated otherwise on a public page, and that was wrong. It is being corrected rather than quietly removed.
GDPR In place An obligation rather than a certificate, so "held" here means the posture is implemented: EU hosting, minimal retention, a documented lawful basis per processing activity, and no special-category data processed at all.
Records of processing and the DPA are available on request
eIDAS Intended, not started Not a certification we hold — a standard we consume. Declarant identity is established by a qualified trust service provider, supervised under eIDAS by ANSSI in France, rather than by a biometric check of our own. No provider is contracted yet; the shortlist is the EU Trusted List, which is public and checkable.
Regulation (EU) 910/2014, as amended — eIDAS Dashboard, eidas.ec.europa.eu/efda
EUCC Does not cover us The Common Criteria scheme certifies ICT PRODUCTS — smart cards, hardware with security modules, and discrete software products with a defined target of evaluation. Apidentity is an operated service, so there is nothing here to evaluate under it. Listed because the question is reasonable and the answer should not be a blank: ANSSI issued Europe's first EUCC certificates in March 2025, to STMicroelectronics and Thales DIS, in exactly those product categories.
Implementing Regulation (EU) 2024/482, under the Cybersecurity Act
EUCS (cloud) Intended, not started The scheme that WOULD cover a service like this, and it is still under development. Its high assurance level is being built on SecNumCloud, which makes the hosting decision a position on EUCS rather than only on sovereignty. Where that stands, precisely, because a status word on its own would be doing work it has not earned: the service is SELF-HOSTED on our own equipment in France, and SecNumCloud is the destination rather than the starting point. Checked in August 2026, the smallest qualified pack at the provider we would use is about €45k a year before support, and the offer actually sized for a service like this is itself still in qualification. So this is targeted and dated rather than claimed — and self-hosting is not a lesser answer to it: no hosting provider is a processor here at all.
Cybersecurity Act (EU) 2019/881 — scheme in preparation
EUDI Wallet scheme Does not cover us Under development, and it certifies wallets rather than the services that read them. It matters to us the other way round: the assurance our declarant check rests on will terminate in an artefact certified under an EU scheme rather than in a vendor's own claim about itself.
Cybersecurity Act (EU) 2019/881 — scheme in preparation
CSPN Not held ANSSI's first-level certification, which EUCC does not replace. Not pursued: like EUCC it evaluates a product, and the thing worth certifying here is the operated service.
ANSSI national scheme
On the European schemes

The European schemes above are published under the Cybersecurity Act (EU) 2019/881 and are voluntary. They define three assurance levels — basic, substantial and high — and at the high level the certificate is issued by the national authority itself, which in France is ANSSI. None of them is a requirement we are failing to meet; two of them do not cover what we are, and the one that would is not finished.

A correction we are making in public

An earlier generation of this product published a page stating ISO 27001 as “SMSI certifié”, with a SOC 2 badge beside it. Neither was true. It is being taken down and this page replaces it.

We are saying so here rather than deleting it quietly, because a company selling verification does not get to be careless about its own claims — and because you would have found out.

We run ourselves through it

Adesio holds an Apidentity certificate, produced by the same engine, against the same registry and the same lists. It does not grade band A. The identity axis is partial, the ownership chain above us is unwalked, and the engine says so rather than making an exception for the company that wrote it.

Check any certificate, including ours.