Trust Center

Built on trust

Infinihash operates compliance, identity and settlement infrastructure for regulated institutions. This page is the honest, current state of our security, compliance, and data posture across KYC, KYT and Rails. We flag what is live, what is in progress, what is on the roadmap, and what we have decided not to do at all. No aspirational certifications.

Last reviewed: 10 September 2026 . Maintained by Infinihash Security.

Where we actually stand

Status reflects current reality. Where a framework is in progress or planning, we say so. We do not claim certifications we have not earned.

In Progress

SOC 2

SOC 2 program in progress — no report issued yet. Pre-attestation security questionnaires available on request.

Planning

ISO 27001

Scoping ISMS, control mapping, and gap assessment. No fixed certification date.

In progress (target Q3 2026)

GDPR

Cookie consent banner is now live estate-wide. Remaining gaps before we claim alignment: (1) ✓ PublishedData Subject Request workflow is now publicly documented, (2) ✓ PublishedRecords of Processing Activities summary is now public, (3) Privacy Policy is self-authored v1 and not yet counsel-reviewed, (4) no Data Processing Agreement is available for signature yet — a template written against the actual data flows described on this page is drafted and with counsel; we are not offering one until it can be executed, and we do not claim standard contractual clauses we have not put in place. Remediation tracked under internal #1820.

In progress (target Q3 2026)

CCPA / CPRA

Privacy notice published and a consumer rights inbox is monitored. Cookie consent layer is now live. Remaining gaps: documented DSR workflow, public RoPA, counsel-reviewed Privacy Policy. Tracked under internal #1820.

Live

BSA / AML Tooling

KYC + KYT products operational. SAR / FinCEN JSON export shipped. Built for regulated DAS and OTC counterparties.

Live

Sanctions Screening

OFAC SDN cryptocurrency addresses screened on every KYT request. UN and EU consolidated lists tracked in roadmap.

Note: GDPR and CCPA do not offer formal certifications. The status above reflects the readiness of our documented controls, not an attestation. Until every gap listed above is closed, we describe ourselves as "in progress" rather than "aligned."

Built for compliance and risk teams

Our customers operate in regulated corners of finance and crypto. The platform was designed around their controls, audit trails, and reporting workflows. Named customer references and case studies are in progress.

Hedge Funds

Counterparty KYT screening, wallet attribution, and SAR-ready transaction monitoring for digital-asset strategies.

Crypto Treasuries

Continuous monitoring of corporate wallets, OFAC screening on inbound flows, and treasury-level KYC for vendors and payees.

Law Firms

Investigative KYT support, on-chain provenance reports, and chain-of-custody exports for regulatory and litigation matters.

OTC Desks

Pre-trade counterparty KYC, address screening on every settlement, and FinCEN-JSON SAR export to satisfy BSA obligations.

What is in the screening graph

KYT screens against an ingestion pipeline of sanctions, stablecoin freezes, and curated threat intelligence. Counts shown are deduplicated addresses currently in the active label set.

SourceCategoryAddressesAcceptance Tier
OFAC SDN (US Treasury)Sanctions656T1 . 100% accept
Stablecoin issuer freezes (USDT, USDC, etc.)On-chain enforcement7,463T3 . accept
ScamSniffer phishing & drainer setThreat intel2,530T4 . evaluated
Aggregate active label setAll accepted sources10,000+Growing toward 260k
The ingestion pipeline pulls from 60+ public intelligence sources across five phases. Every candidate label passes a KYT validation gate before upsert. Sources that fail validation (insufficient signal, disjoint coverage, or unverifiable provenance) are rejected rather than blended.

Identity verification stack

KYC handles document OCR, MRZ extraction, structured field capture, and — since 2026 — an in-house liveness challenge with face match against the document portrait. This page previously described liveness as roadmap; that was stale, and the correction is below.

Document OCR

  • Primary engine: MyAi — a vision model Infinihash runs on its own infrastructure, not a third-party API. Where a deployment has MyAi disabled, Gemini takes the primary position rather than the pipeline failing.
  • Fallback engine: Google Gemini 2.5 Flash, vision-mode prompts. On elevated-risk documents both engines are run and the extractions compared.
  • Not Anthropic: document images are never sent to Claude. An unused Claude OCR code path exists in the codebase and is called by no live route. Claude is used only for AML case narrative text — see Subprocessors below.
  • MRZ extraction on passports and ICAO 9303 IDs
Live

Liveness & face match

  • Three-step browser challenge (look straight / turn left / blink) runs client-side; only the final selfie frame is sent to us
  • Face match of that selfie against the portrait on the submitted ID, scored by a self-hosted vision model. A score below threshold does not silently pass — it retries once, then escalates to manual review
  • Explicit biometric consent is captured and recorded before any selfie is collected
  • What we do not claim: this is our own implementation. It carries no ISO/IEC 30107-3 presentation-attack-detection certification and no independent NIST FRVT benchmark, and we do not present it as a certified anti-spoofing control

Roadmap (not live)

  • Independent PAD certification of the liveness check
  • Re-verification cadence for elevated-risk profiles
  • Mobile capture SDK for camera-controlled doc photos

How money moves, and what we refuse to do

Rails takes a USD invoice, collects it by ACH, and settles it as stablecoin to a wallet the tenant controls. Everything below describes behaviour that is implemented and enforced in code, not intent. Where a capability is missing we name it rather than calling it roadmap.

Live

The money path

  • Invoice in USD, collected by ACH through our regulated payments partner — a payments and stablecoin infrastructure provider, not a bank. We do not describe it as a banking partner because it is not one.
  • Converted and sent as one movement to the tenant's own wallet: USDT on Tron or USDC on Base, chosen per tenant.
  • Infinihash never custodies customer funds. The rail models collection and disbursement as a single transfer, so there is no point at which the money sits in an Infinihash-controlled balance. This is a property of the integration, not a promise about our intentions — it is the same fact that makes managed escrow impossible below.
  • Destination wallets are provenance-checked before they can settle. A wallet that has never been verified against the live environment fails closed and the settlement is declined.
Live

Screening & onboarding

  • Settlement is fail-closed on screening. Every settlement KYT-screens the destination wallet before conversion. No pass, no conversion, no disbursement — an unknown or errored screening result is treated as a failure, never as a pass.
  • Scope of that screening: it covers the destination wallet the funds are going to. It does not screen the tenant's own end customers — that obligation stays with the tenant, and our KYC/KYT products are how they discharge it.
  • Tenant onboarding is KYB run through the regulated payments partner, whose decision we mirror rather than override. A tenant whose KYB is unapproved or rejected cannot settle; an unknown KYB state is not a pass.
  • Velocity caps apply per tenant and are enforced in the same gate.
Not available

Managed escrow and refunds

  • Managed escrow is not available. Funding an escrow returns 409 escrow_hold_unsupported. The rail forwards funds to the destination in one transfer, so an escrow funded through it would report as held while the money had already left. We refuse at the door rather than show a balance that is not there.
  • Refunds are not available. A refund request returns 409 refund_unsupported. No settlement adapter implements a refund leg, so dispute rules that would auto-refund route to human review instead of recording a refund no rail performed.
  • Card collection and split settlement are dropped, not roadmap. We would rather remove them from the surface than leave them advertised and refusing.
  • Do not take our word for it: GET /api/v1/capabilities is unauthenticated and computed from the same adapter the money path uses. It is the authority on what this deployment can do. If it disagrees with this page, believe it.
Live

Reserves and disputes

  • A rolling reserve applies to high-risk verticals — part of a settlement is held back rather than paid out immediately. Every hold is shown in the tenant portal with the date it becomes eligible for release, alongside the reason.
  • Hold durations are not published here because they are not yet ratified. They are deployment configuration pending sign-off, and we will publish them as customer-facing terms when they are decided rather than before.
  • The dispute queue, evidence handling and rules are live. Cases can be raised, evidenced and worked.
  • Nothing populates that queue automatically. No third-party alert vendor (Ethoca, Verifi CDRN, Visa RDR) is contracted. Alerts arrive only through the sources we own — hand-entered, or partner files we load ourselves.
Escrow and refunds are formally out of scope rather than delayed. Holding customer funds, even briefly, is a different regulated activity from moving them, and taking that step would change our licensing and BSA/AML posture. That is a decision for counsel, not an engineering backlog item — so the guards, the documentation and the capabilities endpoint all refuse consistently until it is made.

Encryption, identity, and hosting

Foundational controls. Where a control is partial or vendor-default, we say so explicitly.

Encryption

  • In transit: TLS 1.2+ enforced on all public endpoints, HSTS on production hosts
  • At rest: AWS EBS default volume encryption (AES-256)
  • CMEK / BYOK: on roadmap, not yet available
  • Secrets: AWS SSM Parameter Store, environment-isolated

Authentication

  • Cross-subdomain SSO across all infinihash.com properties
  • MFA available on every Infinihash account
  • Magic-link sign in as a passwordless option
  • JWT-bound sessions, DB-backed token validation per call

Hosting & Infrastructure

  • Primary region: AWS us-east-2 (Ohio)
  • Network edge: Cloudflare tunneled, no public IPs on app servers
  • Single region today . multi-region failover on roadmap
  • Backups: daily Postgres dumps, S3 versioned

Application Security

  • Helmet, rate-limit, timing-safe compares on billing surfaces
  • Admin secrets rotated and never hardcoded in source
  • Internal docs surfaces disabled on production auth
  • Signed releases (Ed25519) for the MyAi agent

Data handling and user rights

We collect the data we need to run identity verification, transaction monitoring, and billing. We do not sell personal data.

Rights we honor

  • Access . request a copy of the data we hold on you
  • Deletion . subject to legal hold and AML retention
  • Correction of inaccurate identity records
  • Portability in machine-readable formats

Retention

  • KYC artifacts retained per BSA/AML rules (typically 5 years post relationship)
  • Legal hold overrides scheduled deletion
  • Operational logs trimmed by TTL configured per service
  • Cookie consent layer is live (Consent Mode v2, Accept/Decline)

Documents

Standing legal pages:

No Data Processing Agreement is available for signature yet. A template written against the data flows described on this page — including the Rails subprocessors below — is drafted and under counsel review. We would rather say that than answer a DPA request with nothing. Email [email protected] to be told when it is executable.

Vendors that process customer data

This list reflects current production subprocessors across KYC, KYT and Rails. Each entry says what that vendor actually receives, not just what it is for. Material changes are announced via email to enterprise customers ahead of go-live.

Amazon Web Services
Compute, storage, secrets, networking. Holds the application databases and object storage, so any personal data we retain rests here.
US-East-2
Cloudflare
Edge, DNS, tunneling, DDoS protection. Terminates TLS in front of our estate, so request metadata and visitor IPs transit it.
Global
Stripe
Subscription billing for Infinihash accounts. Receives billing contact, customer ID and card token; card numbers never reach our servers.
US
Bridge
Rails / BaaS regulated payments partner. Receives tenant KYB data (legal name, entity type, tax identification number, incorporation and operating addresses, business description, website), beneficial-owner and control-person personal data (name, date of birth, residential address, personal tax identification number such as an SSN, and government-ID images), source-of-funds answers, and terms acceptance. On the money path it also receives ACH collection and disbursement instructions including the destination wallet address, chain and amount. Owner personal data and ID images stream through to Bridge and are not persisted by us; business-level identifiers (tax ID, addresses, contact) are retained on the application record.
US
Persona
Identity verification for Bridge. Bridge's identity-verification and screening vendor, which processes the individuals submitted through KYB — identity checks, database verification and sanctions screening — and issues requests for further information directly to the applicant. Personal data reaches Persona via Bridge, not through a direct Infinihash integration. Listed here because it demonstrably processes identity data submitted through our onboarding, and a subprocessor list that stopped at Bridge would not describe the real flow.
US
Google (Gemini)
Vision inference for KYC document extraction. Receives identity-document images. On elevated-risk documents it runs alongside our own model rather than instead of it.
US
Google Analytics & Google Fonts
Website analytics on our marketing pages, gated behind the cookie consent banner, plus web-font delivery. Receives visitor IP address, cookie identifiers and page views. No product or identity data passes through it.
US / Global
Anthropic (Claude)
AML case narrative text generation. Receives the entity name and type plus pass/fail summaries of completed checks — nothing else. It is not part of the document pipeline and never receives identity-document images.
US
Resend
Transactional email (magic links, onboarding invitations, alerts). Receives recipient email address and message content.
US
Two things this list deliberately does not hide. MyAi, the primary vision model in the KYC document pipeline, is not on it because it is not a third party — Infinihash builds and hosts it on its own infrastructure, so document images processed there stay inside our estate rather than going to an external vendor. And the vendors that receive identity data are a short list: Bridge and, through Bridge, Persona for business onboarding; Google (Gemini) for document extraction; AWS for storage. Everything else on this list handles billing, delivery, edge traffic or website analytics.

Report something

For vulnerabilities, incident reports, abuse, or compliance and privacy requests.

Security & Incident Response
Primary security contact. PGP key on request.
Compliance & Privacy
Security questionnaires, vendor onboarding, data-protection and subject-rights requests. No DPA is executable yet — see Privacy above.