Compliance programmes, audit timelines, and readiness evidence
A single view of where each compliance programme stands, what is included in the SOC 2 readiness package, and how to obtain the full evidence under NDA.
Last reviewed: . Live system status: passkeybridge.io/status.
SOC 2 Type II programme
Pre-audit readinessCovering the Security, Availability, and Confidentiality trust services criteria. Evidence is collected and under review. No CPA is currently engaged. The firm name and observation period will be published here once an engagement begins.
The PDF is a public overview. The full evidence package is shared under mutual NDA after security-team review.
Contents of the readiness package
Enterprise prospects under mutual NDA receive each of the following artefacts. The public summary above describes them at a high level.
- Control matrix mapping every Trust Services Criterion to implementing code, configuration, or runbook.
- CI hardening evidence (ci.yml, live-monitoring.yml, memory-verification.yml) and recent run logs.
- Internal pentest suite output covering authentication, RLS boundaries, SSRF surfaces, and rate limits.
- Breakglass session logs showing M-of-N approval and time-bounded access.
- DSAR cadence with cryptographic shredding evidence and sample fulfilment timeline.
- Sub-processor list with executed DPAs and Schrems III hashed-signal architecture diagram.
- Incident response playbooks and 72-hour breach notification runbook (GDPR Article 33).
- Daily codebase sweep aggregating secrets, PII, RLS, bundle, edge, audit, and memory checks.
- 30-day backfill gate on the SOC 2 observation-window opener—refuses to open until shield_health_snapshots has at least 30 calendar days of evidence.
- Cron heartbeat observability across every scheduled compliance job (shield_cron_heartbeat), surfaced in the admin Operations view.
- Per-tenant cost attribution covering edge-function invocations and AI-model spend (shield_function_cost_metrics).
Programme status
Each programme is owned, evidenced, and reviewed at least quarterly. Status reflects the current state, not a target.
SOC 2 Type II
Pre-audit readiness. Evidence collected and under review. Type I targeted Q3 2026; Type II observation window targeted following type i issuance. No CPA is currently engaged.
GDPR & PIPEDA
DPA incorporated into Terms §10. Standalone DPA available on request. DPO contactable at dpo@passkeybridge.io.
WCAG 2.2 AA
Reduced-motion respect, skip-to-content affordances, semantic headings, and aria-live for live regions.
NIST FIPS 203 / 204
Verifiable Credentials are standard W3C VC-JWTs signed with ES256 plus a detached ML-DSA-65 post-quantum signature. Both public keys are published in the tenant DID document, so a credential verifies end-to-end—including its post-quantum layer—with any stock JOSE/VC library. ML-DSA-87 available as Enterprise add-on.
W3C VC 2.0 / OpenID4VP
Conforms to the published specifications; SD-JWT-VC supported.
ISO 27001
On the post-SOC 2 roadmap once the Type II observation window closes.
Related public documentation
Security & Trust
Architectural commitments, cryptography, sub-processors, and breach response.
System status
Public health snapshots for nine independently checked components.
Technical whitepaper
How the platform achieves zero-PII storage, in-request decisions, and post-quantum forward security.
Software Design Specification
Public SDS covering data flow, edge boundaries, and key handling.
Patent portfolio
Active USPTO filings covering the platform's novel mechanisms.
Privacy policy
Data minimisation, retention, DSAR rights, and cross-border transfers.
Direct contact
For diligence questions, vendor security review, or to request an executed standalone DPA, email security@passkeybridge.io. We acknowledge requests within one business day.