SOC2C

Is this your company? Buyers are checking Wicket here. Claim wicketsoft.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Wicket logo

Wicket

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Wicket is SOC 2 Type II compliant. Wicket also holds ISO 27001, GDPR, and NIST CSF.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Wicket is a facial authentication platform provider with patented computer vision AI technology that improves fan/guest/employee experiences, empowers facility staff, and strengthens security. Wicket has been deployed for facial ticketing, credentialing, access control, and payments in numerous sports stadiums, major conferences, and corporate office environments. Wicket is a privacy-first facial authentication company. All of Wicket's facial authentication products are opt-in only. Registered individuals submit their images by choice for frictionless facility access and other benefits. Data i

Compliance & infrastructure

Data handled
Customer personally identifiable informationEmployee personally identifiable informationPersonal health information

Documents

3

Compliance leadership

The person who leads Wicket's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Wicket's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Subprocessors
    List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Wicket SOC 2 compliant?
Wicket is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Wicket ISO 27001 certified?
According to Wicket's public trust center, Wicket is ISO 27001 certified. On SOC2C this listing is Listed.
Is Wicket GDPR compliant?
According to Wicket's public trust center, Wicket is GDPR compliant. On SOC2C this listing is Listed.
Is Wicket NIST CSF compliant?
According to Wicket's public trust center, Wicket is NIST CSF compliant. On SOC2C this listing is Listed.
Is Wicket SOC 2 Type I or Type II?
Wicket is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Wicket

Reproduced from Wicket's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

What is Wicket's approach to Security and Privacy?
Wicket is committed to the responsible use and application of facial authentication technology and, to that end, takes security and privacy very seriously. The platform is entirely opt-in, all personally identifiable information (PII) is encrypted at industry standard levels at rest and in transit, and any PII is never transferred or otherwise utilized for any purpose aside from core product use cases. Wicket never sells any PII. The Wicket platform has been designed and developed in-house and does not have any third-party dependencies at its core. Wicket is GDPR, SOC2 Type II, and NIST CSF compliant, and ISO 27001 certified. For more information about Wicket security and privacy, please visit https://wicketsoft.com/security.
What is the difference between Facial Recognition and Facial Authentication?
A facial recognition system is a technology capable of matching a human face to a digital image of that face. While Wicket’s computer vision algorithms could technically be classified as a facial recognition system, we prefer to use the term Facial Authentication. Facial recognition systems like those used by law enforcement or security agencies (to identify an unknown individual by running an image through an extensive database) are typically based on a surveillance model. Wicket differs from this approach in two ways: Firstly, Wicket has an opt-in-only model. We do not use our technology to keep people out, but rather to let known faces (registered users) in—only people who have explicitly opted into Wicket-powered services can use them. Not only that, but users must willingly provide images of their own face to use our services. Secondly, Wicket’s Facial Authentication system is designed to protect the privacy of those who do not want to be captured at all. To ensure unwilling participants aren’t scanned by Wicket, users must physically present to a Wicket sensor to gain access to confirm that the user is: 1. Enrolled in a Wicket-powered service (by opting in) 2. Eligible for access to that service 3. Granted or denied the service based on their eligibility In short, Facial Authentication verifies the identity of an individual who has already provided consent to be in the system via an opt-in procedure.
Is the Wicket Platform Legal? Does it violate privacy laws?
The term ‘Facial Recognition’ has broad implications and, for many, conjures up concerns about privacy invasions and misappropriation of personal identity. Wicket delivers robust value to the event manager while safely navigating the legal and ethical considerations commonly associated with the technology. The entire platform was developed in-house, on US soil, and does not have any third-party dependencies. It has been architected and deployed to conform to the most stringent privacy regulations and to address the most common ethical considerations. In the U.S., there is no specific federal law relating to facial recognition. However, the FTC has broad authority to bring enforcement actions against companies that participate in unfair or deceptive trade practices relating to biometric data. At the state level, the past few years have seen a number of states enact privacy legislation as more and more states seek to regulate the collection, use, and processing of biometric data and to protect people from unauthorized appropriation of their biometric data. The Illinois Biometric Information Privacy Act (BIPA), enacted in 2008, is the first and most stringent biometrics law in the U.S. and also provides for a private right of action for its violation. The California Consumer Privacy Act (CCPA) of 2018 (amended 2023) provides similar privacy rights to California consumers. Both laws have served as a model for other US state privacy laws. Wicket recognizes and respects these regulations, and we have architected our solutions accordingly. Refer to our privacy policy at https://www.wicketsoft.com/privacy-policy for more information on how Wicket complies with privacy laws.
Is Wicket an Artificial Intelligence (AI) System subject to the EU AI Act?
The EU AI Act was adopted in 2024 with the goal of promoting trustworthy AI in the EU market, and provides a risk-based approach to classifying AI systems. Wicket's platform has been evaluated by third parties in the EU with legal expertise in the area of EU privacy law, including the EU AI Act. The portion of the platform that provides the computer vision algorithm is considered an AI System, and has been classified as "limited risk" because it is a verification system that uses biometrics. Although Wicket is not a high risk AI System, as defined by the EU AI Act, we do have a transparency obligation. This obligation is met for platform users through various means, including onsite support with our Clients, training, our Trust Center, and our Privacy Policy.
How has Wicket architected its products to comply with existing biometric data-related laws?
All deployments for access control, credentialing, ticketing, and purchasing are expressly conditioned upon obtaining the informed written consent of the fan or user. All users must affirmatively consent to the use of their biometric identifier after reviewing our privacy policy and before uploading their image into the system. After that, only the faces of consenting users who present themselves to a Wicket Access sensor are scanned, and only scanned images are stored.