generated: '2026-07-21' method: searched source: https://validit.ai/faq/ description: >- Compliance and security posture published by Valid.it (Validit.ai) on its FAQ page (Privacy & Security section). Valid.it publishes no public API documentation or OpenAPI specification, so no spec-derived conformance (OAuth2/OIDC, RFC 9457, pagination, idempotency) can be asserted; this file captures the company's own published claims verbatim from the FAQ. standards: - id: soc2 conforms: true evidence: >- FAQ: "We conduct frequent penetration tests and SOC 2-certified security audits to proactively identify and mitigate vulnerabilities." Primary infrastructure (AWS) is described as operating in a "GDPR-compliant, ISO 27001, and SOC 2-certified environment." - id: iso27001 conforms: false evidence: >- ISO 27001 is claimed only for the underlying AWS infrastructure environment ("Our primary infrastructure provider, Amazon Web Services (AWS), operates in a GDPR-compliant, ISO 27001, and SOC 2-certified environment"), not as a company-level Valid.it certification. - id: gdpr conforms: true evidence: >- FAQ: "Valid.it aligns with the General Data Protection Regulation (GDPR) by ensuring that all personal data is processed lawfully, fairly, and transparently. As a Data Processor, we operate strictly under our customers' instructions." Built-in Data Processing Agreement (DPA) in terms; cross-border transfers via Standard Contractual Clauses (SCCs); AWS Ireland region offered. - id: pipeda conforms: true evidence: >- FAQ documents alignment of data retention/minimization and vendor risk management with PIPEDA (Canada) alongside GDPR and POPIA. - id: popia conforms: true evidence: >- FAQ: vendor due diligence "to ensure compliance with GDPR, PIPEDA, POPIA, and other global regulations"; platform supports South African transparency requirements via customer privacy notices. - id: appi conforms: true evidence: >- FAQ: "Customers can define consent mechanisms within our platform to comply with APPI's guidelines on explicit user consent" (Japan). - id: ny-shield conforms: true evidence: >- FAQ: NY SHIELD Act section — "We apply encryption (AES-256, TLS 1.2/1.3), MFA, and access controls to prevent unauthorized access" with real-time monitoring, anomaly detection, and incident-response practices for breach notification support. - id: israeli-privacy-protection-law conforms: true evidence: >- FAQ cites the Israeli Privacy Protection Law among the retention and minimization regimes the platform is designed to satisfy. - id: tls-in-transit conforms: true evidence: 'FAQ: "TLS 1.2/1.3 for data in transit"; AES-256 encryption at rest.'