Hashed at source
PII is hashed with SHA-256 before delivery.
COMPANY / SECURITY
How Datahash handles data, consent, encryption, hosting, and audits. Verified continuously, published in the open.
SOC 2 Type II
ISO/IEC 27001 controls monitored live on trust.datahash.com
PII is hashed with SHA-256 before delivery.
No customer PII is stored on the Datahash host server in Datahash Cloud.
In Datahash Core, all data stays inside the customer’s own VPC.
Signals (hash + route)
Raw identifiers are hashed before they move. Destinations receive only what their spec requires.
Independent audits, not self-assessments. Every document below is available through the Trust Center.
Audit complete
Independent audit of security, availability, and confidentiality controls, operating over time rather than at a point in time. Full report available under NDA.
Certified
Certified information security management system covering how risk, operations, vendors, and people are governed across Datahash.
External penetration test and web application assessment by an independent security firm, repeated every year. The latest summary report is published on the Trust Center.
A documented incident response plan with named owners. Every report to security@datahash.com is investigated, recorded, and tracked to resolution.
TLS 1.2 or newer on every connection, encrypted storage underneath.
AWS across regions. Datahash Core deployments can be locked to a region.
Minimization and consent are built into how Signals routes data, not bolted on.
Consent-aware routing: signals move only when the user’s consent state allows it.
Available on request for teams handling regulated health data.
Security controls are checked continuously and published live on the Trust Center.
No. Identifiers are hashed with SHA-256 at source. In Datahash Cloud no PII is stored on the host server; in Core nothing leaves your VPC.
Yes. Datahash Core is region-lockable; Cloud hosting is region-flexible on AWS.
Request them on trust.datahash.com. The SOC 2 Type II report is shared under NDA; the ISO 27001 certificate and pentest summary are available the same way.
Email security@datahash.com. Reports are acknowledged, investigated, and tracked to resolution under our incident response process.
SECURITY REVIEWS
We answer security questionnaires quickly, and most documents are one click away on the Trust Center.