PasskeyBridge

Compliance & Privacy · 2026-03-05

Reg S-ID Compliance Without Storing a Single Phone Number

By J. W. Bouckaert

Reg S-ID Compliance Without Storing a Single Phone Number

The regulation

SEC Regulation S-ID (17 CFR §248.201) requires financial institutions to develop and implement a written Identity Theft Prevention Program. The rule applies to broker-dealers, investment advisers, and any entity that maintains "covered accounts"—which, in practice, means any financial account with a reasonably foreseeable risk of identity theft. It mirrors and extends the FTC's Red Flags Rule guidance for businesses.

The mandate is clear: detect, prevent, and mitigate identity theft. But the regulation doesn't prescribe how.

The PII liability trap

The conventional approach stores phone numbers, addresses, and government IDs alongside account records. This creates a paradox: the data you collect to verify identity becomes the data attackers want to steal.

Every stored phone number is a liability. Every plaintext identifier widens your breach radius. And every DSAR (Data Subject Access Request) under GDPR or CCPA requires you to locate, export, and potentially delete that data.

There's a better way.

Zero-PII identity verification

PasskeyBridge's zero-PII architecture satisfies Reg S-ID requirements without storing a single piece of personally identifiable information:

Signal-based threat detection (Pillar I)

Carrier signals (SIM swap, number port, call forwarding) detect identity threats in real-time. But the phone number that triggered the signal is keyed-hashed with HMAC-SHA-256 under a server-held pepper before any persistent storage—non-enumerable, unlike a plain SHA-256 of a phone number. Your audit trail proves you detected the threat—without exposing the phone number. For the full picture of carrier signals, see The Carrier Signal Landscape in 2026.

The response is equally critical. PasskeyBridge executes your playbook inside the same request, so you can demonstrate automated mitigation, not only detection.

Verifiable credential verification (Pillar II)

When Reg S-ID requires you to verify a customer's identity, W3C Verifiable Credentials 2.0 let users prove who they are without transmitting PII. The credential issuer (a bank, government, or trusted third party) signs the claim. PasskeyBridge verifies the signature. The claim itself is never stored.

This satisfies the "reasonable policies and procedures" standard in §248.201(d) while eliminating the storage liability entirely.

Biometric binding (Pillar III)

WebAuthn passkeys bind identity to device-level biometrics. The biometric data (fingerprint, face scan) never leaves the user's Secure Enclave. PasskeyBridge stores only the credential public key—mathematically unforgeable and non-identifying.

This creates a chain: the carrier signal proves the phone line is secure, the verifiable credential proves the person is who they claim, and the passkey proves the person is physically present. No PII stored at any step.

Mapping to Reg S-ID requirements

  1. Identify relevant Red Flags—PasskeyBridge's 7 canonical signal types map directly to identity theft indicators
  2. Detect Red FlagsIn-request signal processing with HMAC-SHA256 verification
  3. Respond to detected Red Flags—Automated playbook execution with parametric revocation
  4. Update the Program—Real-time analytics dashboard with usage metering and trend analysis

The audit evidence

When regulators or auditors ask for evidence of your Reg S-ID program, PasskeyBridge provides:

  • Append-only audit log with actor context and timestamped action results
  • Signal processing metrics (volume, response times, playbook execution counts)
  • Zero-PII design documentation—no sensitive data to produce in discovery
  • SOC 2 Type II aligned controls across all five Trust Service Criteria

For enterprises using AI agent delegates, the audit trail extends to every autonomous action, proving that agents operated within scoped permissions.

Get compliant without the liability

Reg S-ID doesn't require you to store phone numbers. It requires you to detect and respond to identity threats. PasskeyBridge does both—with zero PII, in-request response, and a compliance-ready audit trail.

Get started free →

Start free · Test the API