We Run on a Testnet, We Hold No Certification, and Here Is What We Actually Delete

Nothing here is legal advice.

That paragraph is the page. Everything below is detail.

Why we lead with that

A security page usually opens with badges. Ours cannot, because we hold none, and a page that buries that under architecture diagrams is doing the burying deliberately.

Candor here is the strategy, not a hedge. A buyer who discovers our certification status during due diligence learns two things, and the second one is about us.

What we delete, and when

This is the part most vendors describe vaguely, so here it is concretely.

Identity documents purge 30 days after capture. The field that governs it is set on the record itself, not by a policy document somebody has to remember.

Session recordings purge 365 days after capture. Longer, deliberately, because a recording is audit evidence for a check that a supervisor may review long after the fact. The retention period is set explicitly on each recording rather than inherited from a default.

And the deletion actually runs. A scheduled job sweeps records past their purge time, deletes the stored media, and marks the record. It is enabled in production, it runs daily, and its most recent pass completed successfully in non-dry-run mode.

That last sentence is the one that matters. A retention window nobody enforces is a policy, not a control, and the difference is invisible from outside.

What we do not delete, and cannot

There is no self-service account deletion, and no data-subject erasure endpoint.

If you ask us to erase an account today, there is no route in the product that performs it. The retention sweep removes the documents and the recordings on their schedule; it does not remove an account on request.

That is a real gap and we are not going to describe it as a roadmap item to soften it. If your obligations require an erasure path on demand, we do not have one, and you should weigh that as a present fact rather than a scheduling question.

Why the credential design reduces what is at risk

The strongest security property here is not a control. It is that a verifier can receive less.

Selective disclosure means a business checking a customer can be given the specific fields it needs and a proof that an issuer signed the whole set, rather than the document itself. Data that was never transmitted cannot leak from the system that never held it, and that is worth more than most of the controls that would appear on a certification checklist.

Those are different properties and we would rather you know which one you are getting.

The certification position, with the date

SOC 2 Type II, ISO 27001 and eIDAS qualified trust service provider status are targeted for 2027.

None is held. None is in progress. No assessment has been commissioned and no accredited body has looked at anything we run. The 2027 figure is a target we are stating publicly so it can be held against us, not an assessment timeline that already exists.

If a badge, seal or checkmark implying any of these ever appears on a Solidus surface, it is wrong, and we would like to be told where.

What a buyer should ask us, and our answers

"What has been independently validated?" Nothing.

"What is your retention, and does the deletion run?" Thirty days for documents, three hundred and sixty-five for recordings, enforced by a scheduled job that runs daily and completed its last pass successfully.

"Can I request erasure of an account?" No. There is no such path today.

Nobody outside Solidus has relied on one in production.

Where this leaves a decision

If your procurement requires a current SOC 2 or ISO 27001 report, we cannot satisfy it in 2026 and you should not run a pilot on the assumption that we will.

If your concern is how much of your customers' data ends up sitting in systems that then have to protect it, the architecture reduces that materially, the retention windows are short and actually enforced, and the erasure gap above is the thing to weigh against it.

Keep reading

Powered by the Protocol

Solidus Verify is one product on the Solidus Network.

Explore the consensus, the validator economics, and the other products on the same identity layer.

We Run on a Testnet, We Hold No Certification, and Here Is What We Actually Delete · Solidus — Solidus Verify