Trust Center

Compliance programmes, audit timelines, and readiness evidence

A single view of where each compliance programme stands, what is included in the SOC 2 readiness package, and how to obtain the full evidence under NDA.

Last reviewed: . Live system status: passkeybridge.io/status.

SOC 2 Type II programme

Pre-audit readiness
Type I target
Q3 2026
Type II window opens
Following Type I issuance

Covering the Security, Availability, and Confidentiality trust services criteria. Evidence is collected and under review. No CPA is currently engaged. The firm name and observation period will be published here once an engagement begins.

The PDF is a public overview. The full evidence package is shared under mutual NDA after security-team review.

Contents of the readiness package

Enterprise prospects under mutual NDA receive each of the following artefacts. The public summary above describes them at a high level.

  • Control matrix mapping every Trust Services Criterion to implementing code, configuration, or runbook.
  • CI hardening evidence (ci.yml, live-monitoring.yml, memory-verification.yml) and recent run logs.
  • Internal pentest suite output covering authentication, RLS boundaries, SSRF surfaces, and rate limits.
  • Breakglass session logs showing M-of-N approval and time-bounded access.
  • DSAR cadence with cryptographic shredding evidence and sample fulfilment timeline.
  • Sub-processor list with executed DPAs and Schrems III hashed-signal architecture diagram.
  • Incident response playbooks and 72-hour breach notification runbook (GDPR Article 33).
  • Daily codebase sweep aggregating secrets, PII, RLS, bundle, edge, audit, and memory checks.
  • 30-day backfill gate on the SOC 2 observation-window opener—refuses to open until shield_health_snapshots has at least 30 calendar days of evidence.
  • Cron heartbeat observability across every scheduled compliance job (shield_cron_heartbeat), surfaced in the admin Operations view.
  • Per-tenant cost attribution covering edge-function invocations and AI-model spend (shield_function_cost_metrics).

Programme status

Each programme is owned, evidenced, and reviewed at least quarterly. Status reflects the current state, not a target.

SOC 2 Type II

Security, Availability, Confidentiality
In progress

Pre-audit readiness. Evidence collected and under review. Type I targeted Q3 2026; Type II observation window targeted following type i issuance. No CPA is currently engaged.

GDPR & PIPEDA

EU/UK and Canadian data protection
Operational

DPA incorporated into Terms §10. Standalone DPA available on request. DPO contactable at dpo@passkeybridge.io.

WCAG 2.2 AA

Public surfaces accessibility
Operational

Reduced-motion respect, skip-to-content affordances, semantic headings, and aria-live for live regions.

NIST FIPS 203 / 204

Post-quantum cryptography
Operational

Verifiable Credentials are standard W3C VC-JWTs signed with ES256 plus a detached ML-DSA-65 post-quantum signature. Both public keys are published in the tenant DID document, so a credential verifies end-to-end—including its post-quantum layer—with any stock JOSE/VC library. ML-DSA-87 available as Enterprise add-on.

W3C VC 2.0 / OpenID4VP

Verifiable credential issuance and presentation
Operational

Conforms to the published specifications; SD-JWT-VC supported.

ISO 27001

Information security management
Planned

On the post-SOC 2 roadmap once the Type II observation window closes.

Direct contact

For diligence questions, vendor security review, or to request an executed standalone DPA, email security@passkeybridge.io. We acknowledge requests within one business day.