Documents
Including the ones that do not exist. An absence stated is worth more than an absence you have to infer.
The verification standard
Public
What is checked, what each outcome means, and what the engine refuses to conclude.
Data processing agreement
On request
Our standard DPA, for customers and prospects.
Records of processing (GDPR Art. 30)
On request
What is processed, why, on what basis, and for how long.
SOC 2 Type II report
Does not exist yet
No audit period has begun, so there is no report to withhold. When there is one it will be available to customers under NDA, and this line will say so.
Penetration test report
Does not exist yet
No third-party test has been commissioned. Stated because its absence is the answer.
Asking for one
Email bertier@ades.io with the document and who is asking. There is no form here on purpose: a request form that routes into a queue nobody has staffed is worse than an address that reaches a person.
If you are doing vendor due diligence on us
The honest summary is that Apidentity is early. There is no SOC 2 report and no penetration test, and this page says so rather than implying a maturity we have not reached. What there is instead is on the controls page: mechanisms you can name, each with the test that fails if it stops being true.
If that is not enough for your process, it should not be. Say so and we will tell you when it changes.