Get started

Security & privacy

Built like a bank would demand

The single most important thing on this page: you never receive your users’ identity documents, and neither do we. Photos of passports and selfies stay with the verification company that captured them. We keep the outcome of the check, a reference number, and a fingerprint of each document — enough to prove the check happened, not enough to expose anyone if it leaked.

That is not only a privacy position. It is the difference between an incident that costs you an apology and one that costs you a regulatory filing.

The controls behind it

  • Keys that do one job. Each product gets its own API key, limited to what it needs, and larger customers can require every request to be signed so a stolen key alone is not enough.
  • Locked to your network. Restrict an account so it only accepts requests from your own servers’ addresses.
  • An audit trail that cannot be quietly edited. Every entry is chained to the one before it, so an export can be checked for tampering by anyone you hand it to — including a regulator.
  • A freeze switch. Compliance staff can suspend an account immediately, with the evidence attached to the record.
  • Abuse controls. Signup limits, shared-device clustering, and access that only widens after a clean verification.
  • Deletion on a schedule. Set how long personal data is kept and it is removed on time, without breaking the audit trail’s integrity.

Where data lives: a single documented region for all customers. Per-customer data residency is not something we offer today, and we would rather say so here than in a security questionnaire later.

Security reviewers: request our institutional controls brief under NDA — it is not published with the public developer docs.

Security · Identity Inc.