Verax
← All vendors

D-ID

medium risk

Generative AI / Synthetic Mediad-id.comverified 2024-05-22profile 85% complete

Data-handling profile

Trains on input
No — does not train on customer inputs
Retention
Enterprise: Data deleted upon request or contract termination. Consumer: Assets stored in user account until deleted by user.
Data region
AWS (US-East-1, EU-Central-1)
Certifications
SOC 2 Type IIISO 27001ISO 27017ISO 27018
DPA available
Yes
Breach history
None reported
EU AI Act
D-ID implements mandatory watermarking (D-ID watermark or metadata) for synthetic content in compliance with emerging generative AI transparency requirements.

Sources

Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.

Control mapping

Obligations this vendor triggers, each attributable to the fact it rests on — for your supplier register, not a compliance determination.

  • EU AI Act Art. 50 Transparency obligations for AI systemsok

    trains_on_input = no. Vendor states inputs are not used for training.

  • EU AI Act Art. 26 Obligations of deployers of high-risk AI systemsapplies

    Applies to your organisation as deployer, independent of vendor. Assign human oversight, keep logs, and monitor operation where this tool is used in a high-risk context (Annex III duties apply from 2 Dec 2027).

  • ISO/IEC 27001 A.5.19 Information security in supplier relationshipsapplies

    D-ID processes organisational data as a supplier. Include this vendor in the supplier register and risk assessment.

  • ISO/IEC 27001 A.5.20 Addressing information security within supplier agreementsok

    dpa_available = true. A data processing agreement is available and should be executed.

  • ISO/IEC 27001 A.5.23 Information security for use of cloud servicesapplies

    Cloud AI service; trains_on_input = no. Define acceptable-use and configuration rules for this cloud service.

  • ISO/IEC 42001 A.10.3 Suppliers of AI systems and servicesapplies

    certifications: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018 No AI-management certification identified; assurance must come from your own supplier assessment.

  • GDPR Art. 44–49 International transfers of personal dataok

    data_region = AWS (US-East-1, EU-Central-1). Processing region is within the EU/EEA.

  • NIS2 Art. 21(2)(d) Supply chain securityapplies

    AI vendor forms part of your ICT supply chain. In scope for entities covered by NIS2; include in supply-chain risk measures.

  • DORA Art. 28 General principles for ICT third-party riskapplies

    AI vendor is an ICT third-party service provider. For financial entities: register of information and contractual requirements apply.

Watch this vendor

Get an email the day D-ID changes what it does with your data. Your address is never shown publicly or shared.

Change history

No material changes recorded since monitoring began.