Legal information
Trust center
The documents and the answers a buyer's security review asks for, gathered in one place.
Last updated [DATE]
DraftThese documents are drafted and complete, but the contracting entity is being incorporated and counsel has not signed them off yet. Three points remain explicitly open and are marked in the text: the entity and the governing law, the liability cap in the terms of service, and the identity of the data protection officer.
1.Security overview
The security page describes the controls one by one: encryption, identity, authentication, authorization, data protection, audit, key management, infrastructure, data residency, compliance, incident response and responsible disclosure.
Every line there describes a control that exists in the product today, or says plainly that it does not yet. It is the first page to read before a questionnaire.
2.Architecture and standards
The technology page presents the nine layers from the person to the proof, the table of implemented standards, the format of the evidence bundle, and a fingerprint demonstration that runs in your own browser.
No proprietary format sits on the path to proof: X.509, Argon2, AES-256-GCM, SHA-256, ECDSA, RFC 3161, PAdES B-LTA, C2PA, Merkle tree, OpenTimestamps.
3.Certifications: what is in place, what is in progress
In place: RFC 3161 electronic timestamps, signed C2PA provenance manifests, OpenTimestamps anchoring on Bitcoin, a Merkle chained audit log with sealed checkpoints, GDPR-compliant erasure that keeps the proof, a public evidence bundle verifiable offline.
In progress: a contract with a qualified timestamp provider, C2PA conformance with a Trust List authority, legal review of advanced signature levels.
Nothing on this site claims a certification that is not in place. When one of them lands, this list is what changes.
4.Sub-processors
Three sub-processors, and what each can see:
- Scaleway (France, fr-par) — hosting, database, object storage, key and secret management. Holds the encrypted data; does not hold the content keys in clear.
- Cloudflare — the edge: web application firewall, DDoS mitigation, rate limiting. Handles requests, never content in clear.
- Resend — transactional email. Receives the recipient's address and the content of the message sent.
5.Incident response
In the event of a data breach, we notify the competent authority without undue delay and within the deadline the applicable law imposes, according to the deployment model in place — and inform affected customers where the risk is high.
[PROCESS] — the detailed incident response process is being written and will be published on this page.
6.Responsible disclosure
Report any vulnerability to security@iron-id.io. We acknowledge within two business days and will bring no action against research carried out in good faith, on the terms of the acceptable use policy.
We keep you informed of the fix and, if you wish, credit you publicly once the patch is deployed.
7.Security questionnaires
For a security questionnaire, an architecture review or a threat model, write to contact@iron-id.io. An engineer answers; it is not a task delegated to a sales team.
The contractual documents — DPA, service level agreement, localisation clauses — are provided with the quotation for Enterprise integrations and sovereign deployments.
Get started
See IRON ID for your organization.
Request a demo of the Platform, join early access to be onboarded in the first cohorts, or request a quote for a KYC or Sign SDK integration.
Reply within two business days · contact@iron-id.io