Skip to main content
FaceSign is designed to operate within strict regulatory frameworks. This page covers how FaceSign aligns with GDPR, CCPA, BIPA, SOC 2, ISO 27001, and PSD3, and what documentation is available for your compliance team.

GDPR

FaceSign operates as a data processor under the General Data Protection Regulation. Your organization is the data controller.
Biometric data is classified as special category data under GDPR Article 9. Your organization must establish a lawful basis for processing special category data (typically explicit consent or substantial public interest) before initiating verification sessions.

CCPA

FaceSign operates as a service provider under the California Consumer Privacy Act and CPRA amendments.

BIPA

The Illinois Biometric Information Privacy Act imposes specific requirements on the collection, storage, and use of biometric identifiers.

SOC 2 Type II

FaceSign is pursuing SOC 2 Type II certification.
SOC 2 Type II certification is not yet complete. Contact security@facesign.ai for the current status and to request a copy of the report when available.

ISO 27001

FaceSign is built to ISO 27001 security standards following secure-by-design and privacy-by-design principles.

PSD3 Strong Customer Authentication

The revised Payment Services Directive (PSD3) introduces stricter requirements for Strong Customer Authentication (SCA) and shifts liability for coached transfer fraud to payment service providers.

Coercion detection as a PSD3 compliance tool

Under PSD3, a payment provider that processes a coached transfer may be liable for the loss. Traditional SCA (OTP + password) cannot detect coaching. FaceSign’s coercion detection creates an auditable record that the user was — or was not — acting freely at the moment of authorization. This gives providers:
  • Evidence of due diligence — The provider took steps beyond standard SCA to verify the user’s state of mind
  • A decision point — High coercion risk scores can trigger manual review or transaction hold before funds are released
  • Regulatory documentation — Timestamped, structured data suitable for regulator requests

Available documentation

Next steps

Security Architecture

Technical details on encryption, HSM tokenization, and data flow.

Biometric Data Handling

Retention periods, deletion rights, and data subject access.

Coercion Detection

How FaceSign detects duress and supports PSD3 compliance.