Tea, the safety app that asked women to submit a selfie and a government ID before they could use it, had two separate security failures within the same week last year. An unsecured cloud storage bucket exposed roughly 72,000 images, including around 13,000 government IDs and selfies, some still carrying GPS metadata that let at least one bad actor map where affected users lived. Days later, a security researcher found a second, unrelated database holding more than a million private messages, sitting open with no authentication at all. Tea had told users their ID images were deleted immediately after verification. They weren't.
I've written before about breaches that hand fraudsters the raw material to impersonate someone else — stolen numbers and files that get used later, somewhere else, by someone else. This one happened at the source. The identity verification step itself, the part meant to establish trust, is where the exposure occurred, and the specific failure was that what Tea told users didn't match what Tea was actually doing.
Tea had a privacy policy that said reasonable things about data handling — that they would delete all of their users’ personally identifiable information. That's what makes this breach worth discussing here: a written promise, on its own, tells a user nothing about whether that promise is being kept. Nobody outside the company could check.
Intellicheck collects the same categories of sensitive data Tea did — selfies and government IDs are part of how identity verification works, including for us. So the question worth asking isn't whether we say the right things about protecting that data. It's whether anyone outside the company has actually checked. Intellicheck maintains an independent SOC 2 Type II audit, conducted by A-LIGN, most recently recertified this past July, that examines how we handle customer data over time. We hold ISO/IEC 27001 certification for information security management and ISO 27701 for privacy management, both assessed by outside auditors. Our Biometric Information Policy, published for anyone to read, spells out what biometric identifiers we collect, how long we retain them, and how they're destroyed, built to satisfy Illinois' biometric privacy law, one of the strictest in the country. That's the standard we hold ourselves to. It’s not a description we write about our own practices, but a set of controls verified by someone with no stake in the answer.
Any business that hands identity verification to an outside vendor is vouching for that vendor's data practices to its own customers. When something goes wrong at the vendor, the business that chose them answers for it too. That makes the vetting question worth asking upfront: has this vendor been through a SOC 2 audit recently, and will they share the report? Are their security certifications current, or just listed on a webpage? Do they publish, rather than just claim, what happens to a selfie or an ID image once a decision is made?
A privacy policy is something a company writes about itself. A SOC 2 report is something an outside auditor writes about a company. Those are different documents, and Tea's breach is a good reminder of which one actually tells you something.