Security at Faraday

Securing consumer and customer data is our top priority. We have been in business since 2012 and have handled PII from hundreds of US companies.

Corporate information

Faraday is a Delaware corporation, incorporated in 2012. All Faraday employees are based in the United States and all data processing occurs in the United States.

Logical isolation

As stated in our Terms, your company data is only used to generate your company's predictions. Any data you provide to us is logically isolated to your account and does not benefit other accounts.

SOC 2 Type II audited

Faraday has been SOC 2 Type II audited by Wipfli, LLC since 2020.

Background checks

All Faraday employees who handle consumer or client data must pass a background check using Checkr.com.

HackerOne penetration testing program

Faraday has an active HackerOne penetration testing and bug bounty program.

NIST 800-53 risk management program

Faraday has a NIST 800-53 risk management program that is assessed every quarter by the Faraday risk committee, comprising senior executives and security experts.

CCPA and other US privacy law compliance

Faraday is compliant with various US data privacy laws, including

We will sign Data Protection agreements. We respond to data access, do-not-sell, and data deletion requests. The forms can be found on our Privacy page.

HIPAA compliance

Faraday is a business associate under the Health Insurance Portability and Accountability Act when a covered entity or another business associate discloses protected health information to us. We will sign a Business Associate Agreement before that happens. There is no government HIPAA certification; we do not display HIPAA seals.

Most Faraday work with health-adjacent brands does not need clinical data. Send identity and commercial events (purchases, home try-ons, store visits). Leave prescriptions, exam notes, and claims out of the file. Faraday matches those people into the identity graph and builds models on consumer attributes plus your commercial history. Your first-party data stays in your account and is not used for any other customer.

If a list is PHI, do not email it and do not upload it to an advertising platform as a custom audience unless your counsel has signed off. Hashing an email does not change that. The operational rules, including what to send, how to send it, and which deployments need an authorization, are in HIPAA data in Faraday.

GDPR compliance

Faraday is compliant with the European General Data Protection Regulation. We will sign Data Protection agreements. We will respond to data access, do-not-sell, and data deletion requests. Our method of compliance is to immediately delete all European data as soon as it comes into our possession.

Encryption at rest and in transit

Your data is encrypted at rest and in transit. Unencrypted access and unencrypted storage are disabled.

Subprocessors

Entity nameActivityCountry where processing is performedRegistered addressCountry of registration
Google LLCAnalytics, artificial intelligence, compute, data storage, databases, logging, machine learning, monitoring, networking, securityUnited States1600 Amphitheatre Parkway, Mountain View, CA 94043United States
Amazon Web Services, Inc.DNS, data storageUnited States410 Terry Avenue North, Seattle, WA 98109-5210United States

Want to get updates when we add or remove subprocessors?

Fill out this form to get notified.

Security information and event management (SIEM)

Faraday has a SIEM implemented with Google Cloud Logging and Grafana.

Personally Identifiable Information (PII)

We require PII to match your data into our Faraday Identity Graph containing data about more than 240 million US adults. This can be combinations of:

  • plaintext name
  • plaintext postal address
  • plaintext phone
  • plaintext email
  • SHA-256 hashed lowercase email