Security & trust

Nothing worth stealing.

Most infrastructure asks you to trust that it guards your money, your keys and your customers' faces well. Sidaxis holds none of them. What we keep is proof — verifiable by you, by your customer, and by a regulator.
Request the security packRead the docs
A technician closing a rack door at the end of a quiet data centre aisle
Non-custodial by architectureWe hold no funds, no private keys and no raw biometric. There is nothing in our infrastructure worth stealing on your behalf — the design removes the target rather than guarding it.
Masked by surfaceEvery surface shows only what its holder is entitled to. A party to the transaction sees their own values; a public verifier sees seals, never data. The mask is enforced server-side, not hidden in the UI.
Anchored, not assertedEvery decision, consent and settlement is sealed and independently verifiable. You do not have to trust our word about what happened — you can check it, and so can a regulator.
Residency you choosePick the region your data lives in and the retention window per jurisdiction. Cross-border flows are explicit, logged and revocable — never a silent default.
Biometrics

There is no face database.

The question every security team asks first, answered plainly: we do not keep the biometric. A liveness check happens on the device, a one-way proof comes back, and the image is gone. You cannot breach what was never written down.Read how the attestation works ↗
What we captureA liveness check at the moment of the decision — a live human, present, consenting.
What we keepA cryptographic proof that the check passed, and a one-way template that cannot be reversed into a face.
What we never storeThe image. The video. The raw biometric. There is no gallery of faces to breach, sell or subpoena.
What travelsThe proof, not the person. A verifier learns that a live human consented — nothing about who.
Certifications

Where we actually stand

Stated plainly, including what is still in progress. If a certificate gates your procurement, tell us and we will give you the date.
SOC 2 Type IIIN PROGRESS
Independent audit under way. Report available under NDA on completion.
ISO 27001IN PROGRESS
Certification track started with the same scope as SOC 2.
GDPR & LGPDDPA IN PLACE
DPA signed as processor, sub-processor list published, DPO reachable.
HIPAABAA AVAILABLE
Signed for healthcare workloads, with the audit trail exportable for a regulator.
PCI DSSOUT OF SCOPE
Card data never touches our servers — tokenised at the PSP, so our environment is out of PCI scope rather than certified within it.
WCAG 2.2 AATARGET
Client-facing screens tested against AA; report available on request.
Controls
Encryption — TLS 1.3 in transit, AES-256 at rest, keys rotated and held in an HSM.Access — SSO and SCIM, least privilege by default, every production access logged and reviewed.Isolation — Tenant data segregated at the row and key level; sandbox never touches production.Secrets — No secret is ever sent by e-mail. Keys are shown once, revocable instantly, scoped per workspace.Monitoring — Anomaly detection on every rail, with alerts a customer admin cannot switch off.Recovery — RPO 5 minutes, RTO 1 hour, restore drills run quarterly and reported to enterprise customers.
What an auditor can pull
Every decision with the policy version that produced it
Every consent, with its scope and the moment it was given
Every verification, with the proof and never the biometric
Every settlement, matched to its anchored receipt
Every production access, by person and by reason
A signed export, timestamped, in a format they can read
Exportable by you, without asking us. An audit that depends on the vendor's cooperation is not an audit.
Residency and retention

Your data stays where your regulator expects it.

United Statesus-east · us-westDefault for USD rails
European Unioneu-centralGDPR, data never leaves
Brazilsa-eastLGPD, Pix and Open Finance
On requestYour own regionEnterprise, single tenant
Responsible disclosure
Report — security@sidaxis.com, PGP key published. Acknowledged within 24 hours.Safe harbour — Good-faith research is never pursued legally. Test in sandbox, never against real customer data.Reward — Paid by severity, plus credit on this page unless you prefer to stay anonymous.
security@sidaxis.com ↗
The security packArchitecture diagram, data-flow map, sub-processor list, DPA, BAA, penetration-test summary and the SOC 2 report when it lands. Sent under NDA, usually the same day.Request the pack

Questions security teams ask

If you hold no keys, who does?The customer, or their own custodian. Sidaxis proves that the mandate was given by a live, verified human and that the rail executed it — the assets themselves never pass through us.
Can you read our customer data?Only what the integration needs to run, and access is logged with a reason. Documents land in your own cloud. We never train on any of it, and nothing is shared between tenants.
What happens if Sidaxis disappears tomorrow?Your receipts stay verifiable — they are anchored independently of us. Your documents are already in your own storage. An enterprise contract includes source escrow and an export in a format you can read without our software.
Do you support our SSO and our key policy?SSO and SCIM on every plan above the entry tier. Keys are scoped per workspace, revocable instantly, and never transmitted by e-mail — the dashboard shows the full secret exactly once.
How do we test before trusting you?Sandbox runs the same code path as production, with synthetic identities and no real data. Break it as hard as you like; safe harbour covers good-faith testing.

Put your security team in the room.

Bring your questionnaire. We answer it live, in one call, with the engineer who built the rail — not a form and a two-week wait.
Book the security callHow the platform works
Trust model

A promise is worth what the company is worth the day it changes hands

So read this as three questions about capability, not about intent. What we could do if we wanted to is the only part that survives a change of ownership.
What Sidaxis can doConfirm, and recordTell you whether a live human is present. Tell you whether it is the same human you saw before, using the value derived for you and for nobody else. Record that it happened, and anchor the record so it cannot be rewritten afterwards — not by you, not by us, not by whoever buys us.
What it cannot do, even if it wanted toRebuild a face, or join two recordsProduce anyone’s biometric, because we never received one — the reading happens on the person’s own device and is discarded in the same second. Match the value your bank holds against the value a shop holds, because each is derived against the asking party and we are not a party to that derivation. Move your money, hold your keys, or sign on your behalf.
If acquired, subpoenaed or breachedThe answer is the same three timesA buyer inherits proofs that events happened, not a population’s faces. A subpoena compels what we hold, and what we hold is a hash. An intruder takes the same thing. Your anchored receipts stay verifiable without our cooperation — including if the company stops existing, which is the only version of this promise that is not ours to break.
A promise not to correlate is worth what the company promising it is worth on the day it changes hands. A derivation that makes correlation impossible survives the acquisition, the subpoena and the change of management. That is the difference between a policy and an architecture.Verify a receipt yourself ↗
Sidaxis
Protocol notes, receipt-format changes and status posts. No marketing.
you@company.comSubscribe
2591 Dallas Pkwy, Frisco, TX 75034, USA
sales@sidaxis.com · +1 (786) 932-8007
Sidaxis™ is a trademark of Sieve Technologies, Inc. © 2026 Sieve Technologies, Inc. All rights reserved.