Back to Trust & Security
Authentify

Trust Report

Version 1.0 · Generated October 6, 2026

Executive summary

Authentify is the authorization layer for AI agents acting on behalf of financial institutions and their customers. Every agent action requires proof of specific, scoped approval; every decision is logged to an immutable audit trail. This report summarizes the security architecture, the compliance posture of the infrastructure we run on, and exactly how responsibility is split between Authentify, our infrastructure providers, and you.

Security architecture overview

  • Every API call authenticated with a per-agent key (stored only as a hash) or a short-lived OAuth 2.1 token, over TLS
  • Human approval captured out-of-band, on a separate device or session from the agent
  • One scoped API key per agent. Revoking an agent blocks it on its next call; revoking a key blocks new tokens, and tokens already issued from it expire within 10 minutes. Each approval vote records the approver, their device and IP address
  • TLS 1.3 in transit; AES-256 at rest via Supabase-managed keys
  • Immutable, tamper-evident audit logs with full chain-of-custody attribution
  • Vercel platform DDoS mitigation and rate limiting; every query scoped to the account, with row-level security enabled on every table

Compliance certifications

Vercel infrastructure: SOC 2 Type II (updated 2025), ISO 27001, GDPR Data Processing Agreement. SOC 3 report available on request; see Vercel’s trust center.

Authentify application layer: pre-audit, targeting SOC 2 Type II in Q2–Q3 2027. We’re transparent about this timeline rather than implying a certification we don’t yet have.

Responsibility matrix

Who owns what across the stack. A checkmark means that party is directly responsible for that layer.
LayerAuthentifyVercelSupabaseCustomer
API security
Key management
Audit trails
DDoS / WAF
Encryption at rest
Access policies
Incident response

Contact

Security inquiries, vulnerability reports, and SOC 2 report requests: security@authentify.bz

This report is generated for transparency. For official audit reports, request SOC 2 documentation via security@authentify.bz. When saving as PDF, we suggest the filename Authentify_Trust_Report_2026-10-06.pdf.