Version 1.0 · Generated October 6, 2026
Authentify is the authorization layer for AI agents acting on behalf of financial institutions and their customers. Every agent action requires proof of specific, scoped approval; every decision is logged to an immutable audit trail. This report summarizes the security architecture, the compliance posture of the infrastructure we run on, and exactly how responsibility is split between Authentify, our infrastructure providers, and you.
Vercel infrastructure: SOC 2 Type II (updated 2025), ISO 27001, GDPR Data Processing Agreement. SOC 3 report available on request; see Vercel’s trust center.
Authentify application layer: pre-audit, targeting SOC 2 Type II in Q2–Q3 2027. We’re transparent about this timeline rather than implying a certification we don’t yet have.
| Layer | Authentify | Vercel | Supabase | Customer |
|---|---|---|---|---|
| API security | ||||
| Key management | ||||
| Audit trails | ||||
| DDoS / WAF | ||||
| Encryption at rest | ||||
| Access policies | ||||
| Incident response |
Security inquiries, vulnerability reports, and SOC 2 report requests: security@authentify.bz
Authentify_Trust_Report_2026-10-06.pdf.