Compliance

Reports, not certifications

theauth-go publishes a mapping of library behavior to SOC 2 criteria and a GDPR engineering reference for operators. No third-party audit is published, and nothing here says any deployment is compliant or certified.

Sources and review date

SourceLast reviewed 2026-10-06
Source
SOC 2 control mapping and GDPR engineering reference in theauth-go. The TypeScript side is described in the compliance docs.
Last reviewed
2026-10-06. Summaries on this page are written by hand and checked against the linked documents on that date. The documents themselves are the record.

SOC 2

A mapping, not an attestation

The document maps library behavior to the AICPA Trust Services Criteria. The maintainers wrote it. No auditor has reviewed it.

  • CoverageCommon criteria CC1 to CC9, plus availability, confidentiality, processing integrity and privacy.
  • Per criterionWhat the criterion asks for, how theauth-go helps, and what the operator must implement.
  • Often not addressableSome criteria, such as board oversight and hiring, cannot be satisfied by a library. The document says so.
  • Closing sectionA list of what theauth-go does not provide.
  • RolesThe operator is the data controller. theauth-go is a library with no data processing infrastructure of its own, and its authors are not a sub-processor.
  • Data inventoryThe personal data the built-in storage adapters hold by default, such as email, name, session IP and user agent, and credential hashes.
  • Rights and retentionHow to satisfy data subject rights, retention considerations, data residency and cross-border transfers.
  • Defaults and checklistPrivacy-by-design defaults, and a checklist for the operator.

GDPR

An engineering reference

It is not legal advice and not a statement that any deployment is GDPR compliant.

What we do not claim

  • No certifications. theauth-go is not SOC 2 certified or audited. There is no ISO certificate.
  • No third-party audit is published. Nothing on this site presents an auditor's report.
  • No deployment-level claims. An examination covers an operator's whole system. These documents cover one library's contribution.

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud