Security controls designed for sensitive verification workflows
Security is built into candidate evidence handling, organisation access, payment workflows, and operational review, not bolted on after the fact.
Security principles
Verification platforms handle identity evidence, billing events, workflow decisions, and audit records. Our security posture is shaped around minimizing exposure, restricting access, and preserving reviewability.
The public policy page gives a high-level overview of controls. Detailed architecture, provider-specific pathways, and internal operational procedures remain restricted.
Identity and access
Session controls, email verification, MFA capabilities, role-based access, and privileged admin boundaries help keep sensitive functions scoped to the right operators.
Infrastructure and secrets
Runtime secrets are managed outside source control, and cloud-hosted services are configured for controlled access, audit visibility, and environment separation.
API and webhook protection
Admin-issued API keys, write-operation safeguards, signed webhook verification, and customer-specific integration controls protect machine-to-machine flows.
Payment protection
Checkout and wallet flows are delegated to Stripe-supported payment surfaces so card handling does not become a custom application concern.
Application and data controls
- Candidate evidence and reports are intended to remain in private storage surfaces with controlled retrieval and auditability.
- Verification state changes, admin actions, and sensitive operational updates are captured in platform history so teams can review what happened and when.
- Notification content is designed to avoid exposing unnecessary sensitive detail in email or push channels.
Monitoring and response
- Operational events such as failed jobs, payment webhook handling, queue processing, and scheduler activity can be monitored centrally.
- Incident review includes preserving relevant records, scoping impact, restoring service safely, and preparing required communications where a notifiable threshold is met.
- Security work includes both preventive controls and the ability to investigate workflow history when something unexpected happens.
Shared responsibility
Customers also play an important role in security. Organisation admins should assign permissions carefully, use MFA where available, secure webhook receivers, and review template design so teams are not collecting more evidence than needed.
Need a deeper security conversation?
We can discuss security expectations, administrative controls, and integration requirements with qualified customer and partner teams.