Jump to a popular page, or start typing.

    COMPANY / SECURITY

    Security and compliance at Datahash.

    How Datahash handles data, consent, encryption, hosting, and audits. Verified continuously, published in the open.

    • AICPA SOC 2 badge SOC 2 Type II
    • ISO/IEC 27001 certified badge ISO/IEC 27001

    controls monitored live on trust.datahash.com

    DATA HANDLING

    Principles, not promises.

    Hashed at source

    PII is hashed with SHA-256 before delivery.

    No PII at rest

    No customer PII is stored on the Datahash host server in Datahash Cloud.

    Your VPC, your data

    In Datahash Core, all data stays inside the customer’s own VPC.

    ARCHITECTURE

    Where data lives, and where it never goes.

    • Your website / app
    • Your CRM / POS
    • Your warehouse

    Signals (hash + route)

    1. hash
    2. dedupe
    3. route
    • Ad platform APIs (hashed payloads only)

    Raw identifiers are hashed before they move. Destinations receive only what their spec requires.

    CERTIFICATIONS AND AUDITS

    Certified, tested, and open to scrutiny.

    Independent audits, not self-assessments. Every document below is available through the Trust Center.

    • AICPA SOC 2 badge

      SOC 2 Type II

      Audit complete

      Independent audit of security, availability, and confidentiality controls, operating over time rather than at a point in time. Full report available under NDA.

    • ISO/IEC 27001 certified badge

      ISO/IEC 27001

      Certified

      Certified information security management system covering how risk, operations, vendors, and people are governed across Datahash.

    • Annual penetration testing

      External penetration test and web application assessment by an independent security firm, repeated every year. The latest summary report is published on the Trust Center.

    • Incident response and reporting

      A documented incident response plan with named owners. Every report to security@datahash.com is investigated, recorded, and tracked to resolution.

    Documents
    • SOC 2 Type II report
    • ISO 27001 certificate
    • Pentest summary
    • Privacy policy
    Get them on the Trust Center
    SECURITY PRACTICES

    Controls in day-to-day operation.

    Encryption in transit and at rest

    TLS 1.2 or newer on every connection, encrypted storage underneath.

    Region-flexible hosting

    AWS across regions. Datahash Core deployments can be locked to a region.

    GDPR and CCPA aligned by design

    Minimization and consent are built into how Signals routes data, not bolted on.

    Consent Mode v2 and IAB TCF

    Consent-aware routing: signals move only when the user’s consent state allows it.

    HIPAA-aware workflows

    Available on request for teams handling regulated health data.

    Continuous control monitoring

    Security controls are checked continuously and published live on the Trust Center.

    FAQ

    What security reviews ask.

    Is my customer data ever stored unhashed?

    No. Identifiers are hashed with SHA-256 at source. In Datahash Cloud no PII is stored on the host server; in Core nothing leaves your VPC.

    Can we lock data to a region?

    Yes. Datahash Core is region-lockable; Cloud hosting is region-flexible on AWS.

    How do I get your SOC 2 report or ISO certificate?

    Request them on trust.datahash.com. The SOC 2 Type II report is shared under NDA; the ISO 27001 certificate and pentest summary are available the same way.

    How do I report a security issue?

    Email security@datahash.com. Reports are acknowledged, investigated, and tracked to resolution under our incident response process.

    SECURITY REVIEWS

    Running a vendor assessment?

    We answer security questionnaires quickly, and most documents are one click away on the Trust Center.