Security

Security architecture and disclosure policy for ANIMA Verify and ANIMA Identity.

Security controls

Control areaCurrent status
Transport securityTLS + HSTS enabled
Application headersCSP + permissions policy + referrer policy
Token securitySigned tokens with replay controls
Platform hardeningRate limiting and authenticated control surfaces
SOC 2 Type IIAudit in progress, target Q4 2026
FedRAMPPursuing FedRAMP Low authorization — not currently FedRAMP authorized

Trust evidence and third-party posture references are maintained in the Trust Center.

Vulnerability disclosure

Report issues to security@animaid.to. Policy: /.well-known/security.txt.

Include reproduction steps, impact, and environment context. ANIMA follows coordinated disclosure workflow.