Is this your company?Buyers are checking Wicket here. Claim wicketsoft.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Wicket is a facial authentication platform provider with patented computer vision AI technology that improves fan/guest/employee experiences, empowers facility staff, and strengthens security. Wicket has been deployed for facial ticketing, credentialing, access control, and payments in numerous sports stadiums, major conferences, and corporate office environments. Wicket is a privacy-first facial authentication company. All of Wicket's facial authentication products are opt-in only. Registered individuals submit their images by choice for frictionless facility access and other benefits. Data i
SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Wicket SOC 2 compliant?
Wicket is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Wicket ISO 27001 certified?
According to Wicket's public trust center, Wicket is ISO 27001 certified. On SOC2C this listing is Listed.
Is Wicket GDPR compliant?
According to Wicket's public trust center, Wicket is GDPR compliant. On SOC2C this listing is Listed.
Is Wicket NIST CSF compliant?
According to Wicket's public trust center, Wicket is NIST CSF compliant. On SOC2C this listing is Listed.
Is Wicket SOC 2 Type I or Type II?
Wicket is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Wicket's SOC 2 for a vendor risk assessment?
Yes. Wicket's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Wicket penetration tested?
Wicket hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Wicket's SOC 2 report?
Wicket's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Does Wicket have an ISO 27001 certificate?
Wicket publishes an ISO certificate on its trust center; you can request access through SOC2C.
Is Wicket secure?
Security isn't a single yes/no, but Wicket is SOC 2 Type II compliant and holds SOC 2 Type II, ISO 27001, GDPR, NIST CSF. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Wicket have a bug bounty or vulnerability disclosure program?
Wicket hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@wicketsoft.com or via a /security page (Wicket lists a security contact).
Who are Wicket's subprocessors?
Wicket's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Wicket host or store data?
Wicket's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Wicket's trust center or security page?
Wicket's trust center is at https://trust.wicketsoft.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
What is Wicket's approach to Security and Privacy?
Wicket is committed to the responsible use and application of facial authentication technology and, to that end, takes security and privacy very seriously. The platform is entirely opt-in, all personally identifiable information (PII) is encrypted at industry standard levels at rest and in transit, and any PII is never transferred or otherwise utilized for any purpose aside from core product use cases. Wicket never sells any PII. The Wicket platform has been designed and developed in-house and does not have any third-party dependencies at its core. Wicket is GDPR, SOC2 Type II, and NIST CSF compliant, and ISO 27001 certified. For more information about Wicket security and privacy, please visit https://wicketsoft.com/security.
What is the difference between Facial Recognition and Facial Authentication?
A facial recognition system is a technology capable of matching a human face to a digital image of that face. While Wicket’s computer vision algorithms could technically be classified as a facial recognition system, we prefer to use the term Facial Authentication. Facial recognition systems like those used by law enforcement or security agencies (to identify an unknown individual by running an image through an extensive database) are typically based on a surveillance model. Wicket differs from this approach in two ways: Firstly, Wicket has an opt-in-only model. We do not use our technology to keep people out, but rather to let known faces (registered users) in—only people who have explicitly opted into Wicket-powered services can use them. Not only that, but users must willingly provide images of their own face to use our services. Secondly, Wicket’s Facial Authentication system is designed to protect the privacy of those who do not want to be captured at all. To ensure unwilling participants aren’t scanned by Wicket, users must physically present to a Wicket sensor to gain access to confirm that the user is: 1. Enrolled in a Wicket-powered service (by opting in) 2. Eligible for access to that service 3. Granted or denied the service based on their eligibility In short, Facial Authentication verifies the identity of an individual who has already provided consent to be in the system via an opt-in procedure.
Is the Wicket Platform Legal? Does it violate privacy laws?
The term ‘Facial Recognition’ has broad implications and, for many, conjures up concerns about privacy invasions and misappropriation of personal identity. Wicket delivers robust value to the event manager while safely navigating the legal and ethical considerations commonly associated with the technology. The entire platform was developed in-house, on US soil, and does not have any third-party dependencies. It has been architected and deployed to conform to the most stringent privacy regulations and to address the most common ethical considerations. In the U.S., there is no specific federal law relating to facial recognition. However, the FTC has broad authority to bring enforcement actions against companies that participate in unfair or deceptive trade practices relating to biometric data. At the state level, the past few years have seen a number of states enact privacy legislation as more and more states seek to regulate the collection, use, and processing of biometric data and to protect people from unauthorized appropriation of their biometric data. The Illinois Biometric Information Privacy Act (BIPA), enacted in 2008, is the first and most stringent biometrics law in the U.S. and also provides for a private right of action for its violation. The California Consumer Privacy Act (CCPA) of 2018 (amended 2023) provides similar privacy rights to California consumers. Both laws have served as a model for other US state privacy laws. Wicket recognizes and respects these regulations, and we have architected our solutions accordingly. Refer to our privacy policy at https://www.wicketsoft.com/privacy-policy for more information on how Wicket complies with privacy laws.
Is Wicket an Artificial Intelligence (AI) System subject to the EU AI Act?
The EU AI Act was adopted in 2024 with the goal of promoting trustworthy AI in the EU market, and provides a risk-based approach to classifying AI systems. Wicket's platform has been evaluated by third parties in the EU with legal expertise in the area of EU privacy law, including the EU AI Act. The portion of the platform that provides the computer vision algorithm is considered an AI System, and has been classified as "limited risk" because it is a verification system that uses biometrics. Although Wicket is not a high risk AI System, as defined by the EU AI Act, we do have a transparency obligation. This obligation is met for platform users through various means, including onsite support with our Clients, training, our Trust Center, and our Privacy Policy.
How has Wicket architected its products to comply with existing biometric data-related laws?
All deployments for access control, credentialing, ticketing, and purchasing are expressly conditioned upon obtaining the informed written consent of the fan or user. All users must affirmatively consent to the use of their biometric identifier after reviewing our privacy policy and before uploading their image into the system. After that, only the faces of consenting users who present themselves to a Wicket Access sensor are scanned, and only scanned images are stored.
Does Wicket have a formal Information Security Program? Has it been independently verified?
Wicket has maintained a formal Information Security (InfoSec) Program since 2019 that consists of a managed cloud services provider, automated security compliance software, managed detection and response (MDR) services for vulnerability remediation, static code analysis tools, security benchmarking tools, and various other procedures and documentation that support a robust defense in depth. Two separate audit firms have independently audited Wicket’s platform, and we continue annual audits against multiple security frameworks. Our SOC2 Type 2 attestation report demonstrates our compliance with the security, availability, and confidentiality standards set by the American Institute of Certified Public Accountants (AICPA) as well as the core subcategories of the NIST Cybersecurity Framework. Wicket’s Information Security Management System (ISMS) received initial ISO 27001 certification in April 2023 and undergoes surveillance audits each year until re-certification. In addition, we achieved GDPR compliance in June 2023. Refer to the Resources section in this Trust Center for artifacts related to these third party audits.
With Wicket Access, how is consent obtained?
The individual registration process for our Access product is designed to ensure compliance with privacy laws such as BIPA. When an individual is opting-in to Wicket (as in the case of a fan and facial ticketing, or a guest or employee for access control), a series of informative web pages take the user through the benefits of opting-in, the policy detailing our client’s or Wicket’s biometric data practices, and the terms and conditions that apply in the process of securing written consent. This process can be configured to accommodate any unique aspects of the venue’s use case. Once consent is obtained, a secure link is provided, which only allows the upload of a current photo taken through the user’s device camera. By removing the ability to upload a pre-existing photo, Wicket avoids the possibility of uploading someone’s photo without their permission. Once uploaded, an algorithm evaluates the photo for approval and checks for elements such as size, clarity, lighting, multiple faces, and filters. This ensures that all reasonable precautions are taken to upload only those images that meet the highest standards. The system securely uploads photos of individuals to encrypted cloud storage, where they remain for the duration of their use. Wicket creates an embedding of each source photo, a 3D mathematical representation of the image, and sends these series of numbers to the edge devices for use during the authentication process. Each time an individual interacts with the system, the process repeats. The individual’s photo is turned into an embedding, which is compared to the source embeddings to decide if there is a match. For additional considerations around consent and ensuring compliance with BIPA and other privacy laws, please refer to the Wicket Privacy Policy: https://wicketsoft.com/privacy-policy.
Does Wicket capture Personally Identifiable Information (PII)?
PII is only used when necessary for the stated use of the product, and Wicket makes all efforts to minimize exposure and protect user data at all times. PII is never given, transferred, or otherwise utilized for any purpose other than the expressly stated use of the Wicket product. Wicket never sells any PII. All PII (i.e., name and email address) are securely stored in the cloud at all times. All edge devices use unique identifiers to link mathematical facial representations with their associated profiles. This provides the highest level of security on the edge device. Software platforms that we are integrated with to enable various use cases, such as ticketing and credentialing, provide specific data points that we store to execute each application. These include first name, last name, email address, account ID, and customer name ID. For Wicket Access, all PII is provided by the customer or user (after informed consent) and is encrypted in the cloud at all times while in the Wicket environment.
Does Wicket inadvertently capture footage of fans who have not opted in to the program?
The short answer is “no”. To address the concerns about persons who have not expressly opted into Wicket Access, Wicket has implemented a number of controls to ensure that unconsented images are not captured or stored. Wicket ensures that all authentication solutions (access control, ticketing, payments, etc.) are equipped with identification zone technology that allows for the implementation of front, rear, and side boundaries to be configured so that only the person making an access attempt is targeted in the frame. Additionally, edge devices for these solutions perform real-time analytics such that matched images are securely sent to the cloud server, and background or passive images are deleted. All images retained as part of access decisions are purged from the system per the client’s or Wicket’s terms and conditions, whichever retention policy is shorter in duration.
What if a user wishes to withdraw consent?
Users can easily opt out at any time by emailing us at access-optout@wicketsoft.com. Once consent is withdrawn, relevant images and information are purged.
How does Wicket ensure the security of customer data once obtained?
The Wicket team has taken steps in the design and implementation of our solution to maintain customer privacy and security: - All data is encrypted at industry standard levels both at rest and in transit. Wicket sets up encrypted cloud storage for our client’s images, and analysis of the faces is executed based on a numeric representation of the face - not the source photo itself. This improves security as Wicket does not use images on the edge; - In all product cases, all of the decisions and analyses are made locally (i.e., edge-decision) on the device as opposed to sending data back and forth to a cloud server (i.e., cloud-decision). This helps to minimize the possibility of information being intercepted; - While some competitors' systems rely on a constant flow of data between the camera and a cloud server to make decisions, the Wicket systems are designed to “Match on Device.” Beyond the improved speed and efficiency of this architecture, it also minimizes the amount of data that is flowing back and forth, thus limiting exposure. Additionally, it means that the system can continue to function as expected in the event of a loss of internet connection. Wicket does not use, transfer, or sell images or other personal information it collects for any other purpose, including any law enforcement purpose unless allowed or required by law. Additionally, none of the Wicket solutions use external means to identify unmatched faces. All matching is done within the system based on photos provided by the user or the client after consent has been secured; - None of the Wicket software products record video, nor are they designed to be used as a “live viewer” in the way typical CCTV systems are set up. Because no video is recorded, it can't be viewed or shared.
What steps has Wicket taken to ensure there is no algorithm bias with your technology?
The Wicket algorithm enhancements were developed entirely in-house by our team of scientists based in Cambridge, MA, and we prioritized the need to address the issue of bias. With our Wicket technology, match or verification is done based on a set of data points converted to a unique identifier and is not based on matching a picture. For this reason, performance is limited only by the quality of the source video or images, which are based on a) pose or which way the person is looking, b) occlusion or facial hair, hats, glasses, or masks, and c) illumination or lighting. Therefore, efficacy and accuracy are not dependent upon age, skin tone, gender, etc.