Built for a regulated world
Not bolted-on compliance. Privacy and regulatory adherence built into every layer of the protocol architecture.
Regulatory frameworks
General Data Protection Regulation
EU + EEAPrivacy by design. No PII on-chain. Revoking a DID invalidates credentials derived from it; it does not delete data a verifier still holds. GDPR Article 25 native.
EU Identity Regulation
European UnionCompatible with EU wallet architecture. Cross-border identity recognition.
Financial Action Task Force
GlobalNot implemented. L2/L3 KYC tiers exist; no Travel Rule or IVMS 101 message handling does.
Service Organization Control 2
USA (AICPA)Type II audit in progress, target Q3 2026. Security, availability, and confidentiality trust service criteria.
Payment Services Directive 2
European UnionSCA-compatible credential presentation. Identity verification for open banking.
Health Insurance Portability
USAZero PII stored. User-controlled disclosure. Note: Solidus is not a covered entity — consult legal for HIPAA compliance.
GDPR article mapping
Our approach to each applicable GDPR article. This is posture, not assessed compliance.