ANIMA Trust Center

One architecture. Two products. Defensible controls for ANIMA Verify and ANIMA Identity.

Executive summary

ANIMA is built for bot resistance and identity eligibility verification with zero-tracking architecture and explicit legal/compliance boundaries. This page is the source of truth for trust, control status, and procurement references.

Certification and framework status

FrameworkStatusNotes
SOC 2 Type IIAudit in progressTarget Q4 2026.
ISO 27001Gap assessment in progressScope documentation underway.
FedRAMP Low authorizationPursuing authorizationNot currently FedRAMP authorized.
HIPAASuitable under BAAANIMA does not process PHI.
GDPRDesigned to minimize Art. 4 processingDPIA summary available under NDA.
CCPA/CPRAAligned controlsNo sale of personal information.

Security architecture

See full design controls, cryptographic controls, and disclosure process on Security.

Sub-processors

  • Railway (application hosting)
  • Lemon Squeezy (payments)
  • Resend (email)
  • Supabase/PostgreSQL (data storage)
  • Zoho (business operations)

Incident response

72-hour GDPR breach notification target where applicable. Current target RTO 4h / RPO 1h for production incidents.

Audit reports and NDA process

Control narratives, architecture dossiers, and assurance evidence are available to qualified enterprise buyers under NDA via enterprise procurement workflows.

Last updated: 2026-04-17