Skip to main content

Last reviewed: 2026-09-21

Requests received to date: none.

Phase Two has never received a request from any government or law enforcement agency, in any jurisdiction, for customer data. We publish this count every year whether or not it changes.

We host identity data. That makes the question of what we would do if a government asked for it a reasonable one, and a question you should not have to ask twice or take on trust. This page is the answer.

Why this page exists

Phase Two, Inc., our parent company, is incorporated in the United States. Under the US CLOUD Act, a provider subject to United States jurisdiction can be compelled to disclose data in its "possession, custody, or control" regardless of where that data is stored. Storing your data in Frankfurt does not by itself put it beyond the reach of that statute, and we do not claim that it does.

Our European operating company, Phase Two UK, Ltd, is subject to United Kingdom law, including the UK-US Data Access Agreement in force since October 2022, under which United States authorities can in some circumstances serve qualifying orders directly on United Kingdom providers.

We would rather set out these facts ourselves than have you discover them in a risk assessment. What follows is what we do about them.

How we handle a request

1. It is routed to one place. Any request for customer data, from any authority in any country, goes to our legal contact and to a named officer of the company. Operations and support staff do not respond to such requests and are instructed to forward them unanswered. Send one to legal@phasetwo.io.

2. We check that it is valid and binding. We require lawful process appropriate to the data sought and the jurisdiction claimed. We do not treat an informal approach, a voluntary request, or a request lacking proper legal authority as something we are obliged to answer, and we decline those.

3. We redirect it to you where we can. You are the controller of your end users' data; we hold it on your behalf. Where an authority seeks your data, our first response is that they should direct the request to you. We will say so, and we will tell them how.

4. We challenge overbroad or unlawful requests. Where a request is broader than the law allows, seeks data beyond the scope of the order, is inconsistent with the GDPR or United Kingdom data protection law, or conflicts with our obligations to you, we challenge it — including in court where that is the available route.

5. We notify you. Unless we are legally prohibited from doing so, we tell you before disclosing anything, in time for you to seek your own legal remedy. Where a prohibition is time-limited, we notify you as soon as it lapses. Where we are prohibited indefinitely, we challenge the prohibition.

6. We disclose the minimum. If disclosure is ultimately compelled, we provide the narrowest set of data that satisfies the order. We do not hand over a database because a request named a user.

7. We record it and publish the count. Every request is logged and appears in the annual figure below, to the extent the law permits us to report it.

Transparency report

YearRequests receivedRequests where data was disclosedCustomers affected
2019–2025000
2026 (to 21 September)000

Covers requests from any government, court or law enforcement agency in any jurisdiction for customer data, including requests under the US CLOUD Act, the UK-US Data Access Agreement and United Kingdom domestic process. Updated annually, and sooner if the number changes.

What we cannot promise

We cannot promise that no government will ever compel disclosure of data we hold. No provider with a United States or United Kingdom corporate presence can honestly promise that, and a vendor telling you otherwise is describing a marketing position rather than a legal one.

What we can do is limit what is technically reachable, refuse what is not lawfully required, challenge what is overbroad, tell you when we can, and publish the count. That, plus running upstream Keycloak so that leaving is always available to you, is the whole of our answer.

If that is not sufficient for your risk profile — and for some public sector and critical infrastructure buyers it will not be — self-hosting Keycloak on your own infrastructure is a legitimate conclusion, and our support offering exists for exactly that case. We would rather you ran Keycloak somewhere we do not host it than that you bought a promise from us that we could not keep.