Faraday Company's Data Processing and Security Architecture
Faraday Company stands at the intersection of sophisticated machine learning and stringent data security, serving a massive 240 million US adults through its platform. With capabilities honed through rigorous security audits and compliance frameworks, the company processes 1,500+ consumer attributes while maintaining the tightest security protocols. This technical infrastructure supports a diverse array of legal requirements, from the European GDPR to numerous US state privacy acts, making it one of the most comprehensive data processing environments in the industry. Through its unique Directed Acyclic Graph architecture and rigorous identity resolution processes, Faraday demonstrates how advanced analytics can operate within the most stringent privacy constraints.
Faraday Company maintains a robust security framework compliant with both HIPAA and GDPR regulations, including business associate agreements and data protection agreements. They immediately delete European data upon possession, and all data handling occurs within the United States. The company employs comprehensive encryption protocols, with data protected through encrypted storage and transit, and unencrypted access and storage are disabled. Technical security measures include sophisticated systems for Security Information and Event Management (SIEM), leveraging tools like Google Cloud Logging and Grafana for real-time monitoring.
The company operates under an extensive compliance regime covering numerous US data privacy laws, including the California Consumer Privacy Act, Colorado Privacy Act, and dozens of state-level data protection acts. They maintain annual SOC 2 Type II certification from Wipfli, LLC, as audited since 2020. Compliance assessments are conducted quarterly through the NIST 800-53 risk management program, with evaluations performed by senior executives and security experts.
Faraday implements a multi-layered security infrastructure, including logical isolation of company data to prevent unauthorized access during predictive operations. Employee security is managed through rigorous background checks for personnel handling consumer or client data. The company participates in proactive security programs, including a HackerOne penetration testing initiative designed to identify and address vulnerabilities.
The platform architecture is built on a Directed Acyclic Graph (DAG) structure, supporting efficient data processing while maintaining strict access controls. All development follows a controlled process, requiring employees to create Connections to data sources, build Datasets for data ingestion, define Cohorts to represent target populations, and deploy predictions securely through the platform's API infrastructure.
Faraday's platform architecture is built on a Directed Acyclic Graph (DAG) structure, supporting efficient data processing while maintaining strict access controls. All development follows a controlled process, requiring employees to create Connections to data sources, build Datasets for data ingestion, define Cohorts to represent target populations, and deploy predictions securely through the platform's API infrastructure.
Data engineering capabilities allow the platform to automatically engineer predictors from first-party data, including time-, frequency-, and value-based projections. The system processes 1,500+ consumer attributes across 240MM adults, eliminating the need for users to license expensive third-party data. The platform supports 1000 different products and can map them according to specific rules or supplement with SKU mapping spreadsheets.
The data processing pipeline begins with Connecting to existing data sources (including Snowflake, BigQuery, Postgres, and S3), followed by creating Datasets to import data and defining Cohorts to represent key groups. The platform can handle both aggregated data (rolled up) and event-specific data, with a focus on specific date fields for effective modeling. All events are processed along with associated fields, matched to known identities using an algorithm, and assessed within defined windows.
Before training and inference, the system performs geonormalization to ensure proper feature normalization. The company employs a dynamic prediction system that automatically applies the right model ensemble for a subject's tenure at inference time. All models undergo exhaustive cross-validation, offering fully explainable predictions with optional bias management through AI safety features. Reporting capabilities include at-a-glance performance reporting, feature importance analysis with directionality, and detailed technical reports.
The company employs a multi-layered security infrastructure, including logical isolation of company data to prevent unauthorized access during predictive operations. Employee security is managed through rigorous background checks for personnel handling consumer or client data. The company participates in proactive security programs, including a HackerOne penetration testing initiative designed to identify and address vulnerabilities.
All security operations occur within the United States, and the company has been SOC 2 Type II audited by Wipfli, LLC since 2020, with reports available for 2020-2024. Quarterly NIST 800-53 risk management program assessments are conducted by senior executives and security experts. Technical security measures include sophisticated systems for Security Information and Event Management (SIEM), using tools like Google Cloud Logging and Grafana for real-time monitoring.
The platform architecture includes encrypted storage and transit protocols, with unencrypted access and storage disabled. Data is protected both at rest and in transit using encryption. The company enforces strict data access controls throughout its operations. The security framework supports both European and US compliance requirements, with immediate deletion of European data upon possession and full GDPR compliance through matching personal information into the Faraday Identity Graph, which contains data on 240 million US adults. The Identity Graph utilizes specific data types including plaintext names, postal addresses, phone numbers, email addresses (SHA-256 hashed lowercase), and other personal information as required by GDPR regulations.
The company's security infrastructure is designed to support its comprehensive data processing capabilities while maintaining rigorous security standards across all operations.
Privacy and Compliance
In addition to HIPAA and GDPR compliance, Faraday Company operates under an extensive regime covering numerous US data privacy laws. They maintain annual SOC 2 Type II certification from Wipfli, LLC, as audited since 2020, with reports available for 2020-2024. Compliance assessments are conducted quarterly through the NIST 800-53 risk management program, with evaluations performed by senior executives and security experts. All data processing occurs within the United States, and the company participates in proactive security programs, including a HackerOne penetration testing initiative designed to identify and address vulnerabilities. Employee security is managed through rigorous background checks for personnel handling consumer or client data.
The company maintains immediate deletion of European data upon possession and full GDPR compliance through matching personal information into the Faraday Identity Graph, which contains data on 240 million US adults. The Identity Graph utilizes specific data types including plaintext names, postal addresses, phone numbers, email addresses (SHA-256 hashed lowercase), and other personal information as required by GDPR regulations. Data is encrypted both at rest and in transit, with unencrypted access and storage disabled, and technical security measures include sophisticated systems for Security Information and Event Management (SIEM), using tools like Google Cloud Logging and Grafana for real-time monitoring.
The company's compliance framework covers a broad spectrum of US data protection acts, including the California Consumer Privacy Act, Colorado Privacy Act, Connecticut Data Privacy Act, Delaware Personal Data Privacy Act, Indiana Consumer Data Protection Act (effective 1/1/2026), Iowa Consumer Data Protection Act, Kentucky HB 15 (effective 1/1/2026), Montana Consumer Data Privacy Act, Nebraska Data Privacy Act, New Hampshire SB-255, New Jersey S332, Oregon Consumer Privacy Act, Tennessee Information Protection Act, Texas Data Privacy and Security Act, Utah Consumer Privacy Act, and Virginia Consumer Data Protection Act. Faraday responds to data access, do-not-sell, and data deletion requests through their Privacy page, which includes Data Protection agreements.
To protect user privacy while maintaining robust analytics capabilities, Faraday employs several technical measures. All events are processed along with associated fields, matched to known identities using an algorithm, and assessed within defined windows. The system performs geonormalization to ensure proper feature normalization before training and inference. Users can refresh datasets manually through the dashboard or via API, with the process requiring identical column formats as previous uploads. The company provides detailed technical reports for all models and features, offering transparent documentation of their methodology and infrastructure.
Faraday's platform automatically enriches data through its Faraday Identity Graph, which contains information on 240 million US adults. Each dataset includes a data enrichment percentage, indicating the percentage of distinct identities that have been enhanced with data from the Identity Graph. This process matches personal information using specific data types: plaintext names, postal addresses, phone numbers, and SHA-256 hashed lowercase emails.
The company employs rigorous identity resolution techniques, processing events alongside all associated fields and matching them to known identities through an advanced algorithm. This dynamic approach allows the system to recognize individual behaviors across different events and attributes, providing a comprehensive view of each user's interactions.
Dataset creation begins with the declaration of four core data points: Date, Value, Product, and Channel. While these are the fundamental requirements, businesses can provide additional context through more detailed event descriptions. The platform supports multiple data input methods, including direct CSV uploads and seamless integration with major data warehouses like Snowflake and BigQuery.
Once created, datasets automatically sync with connected data sources. For manual uploads, users must enable the "replace all with latest file" option in the advanced settings and upload files through the dataset's data tab. All uploaded files must maintain the same format as previous submissions. The refresh process displays the new upload date within the dataset's status section.
The platform requires specific date field structures for effective modeling. Known Contacts (KCs) measure the count of distinct identities within a dataset, regardless of their recognition by the Identity Graph. Dataset management tools allow users to delete or archive datasets through both the dashboard interface and API commands, providing flexible control over their data assets.