Subprocessors

Last updated September 14, 2026

HumanAuth runs on a deliberately small set of third-party services. Each one processes personal data only to provide its part of the product to us. This page lists them, and exactly what each handles.

Our compliance posture

HumanAuth is pre-pilot and not yet SOC 2 certified. Our SOC 2 observation period is planned to begin once the first production pilots are live. The certifications listed against each subprocessor below are that provider's own — they do not describe HumanAuth's compliance.

Current subprocessors
How push notifications are routed

Approval requests reach the mobile approver apps through the Expo push notification service, which relays each notification to Apple (APNs) or Google (FCM) for final delivery. Expo and the platform services handle the device push token and an opaque alert payload in transit; they do not receive your approval decisions or the receipts.

What our subprocessors never receive

Your biometric — Face ID or Touch ID — never leaves your device. It unlocks an on-device signing key and is never sent to HumanAuth or any subprocessor. We also do not process payment card data, health data, government identifiers, or advertising identifiers. We use no third-party analytics, advertising, or session-replay tooling inside the product; if that ever changes, the provider will appear on this page first.

Changes to this list

This is a living page. When we add a subprocessor or change the data an existing one handles, we update it here and, for customers under a Data Processing Addendum, give the advance notice their agreement requires.

For the full picture of what we collect and why, see our privacy policy. Questions about a subprocessor or data processing: [email protected]