ALL SYSTEMS OPERATIONAL/LIVE TRUST TELEMETRY

Trust is our protocol.
Security is our foundation.

We eliminate enterprise hiring liability by removing centralized data storage entirely. Explore our compliance certifications, security architecture, and independent audit reports.

CERTIFICATIONS & STANDARDS

Continuous compliance assessed by independent auditors.

We adhere to strict international regulatory frameworks and undergo recurring third-party audits.

Certified

SOC 2 Type II

Annual Audit (2026)

Independently audited by top-tier CPA firms assessing security, availability, and strict confidentiality controls.

Certified

ISO/IEC 27001

ISMS Certified

International gold standard for Information Security Management Systems covering infrastructure, personnel, and operations.

Compliant

GDPR & CCPA

Privacy by Design

User-directed data exchange. No centralized credential storage or persistent profiling without explicit cryptographic consent.

Standard

W3C DID & VC Native

Open Specification

Built natively on W3C Decentralized Identifiers and Verifiable Credentials, guaranteeing cross-border enterprise interoperability.

Compliant

DPDP & Global Privacy

Cross-Border

Engineered to comply with the Indian DPDP Act, Singapore PDPA, and global data residency requirements.

Honeypot Immune

Zero-Storage Protocol

Architectural

PIX is a stateless trust intelligence router. Credentials are never stored on our servers, eliminating mass data breach liabilities.

CORE ARCHITECTURE

Security engineered into every packet.

Traditional platforms protect databases with firewalls. People Index solves security by ensuring there is no database to breach.

01 // Honeypot-Immune Architecture

Zero Centralized Storage

Unlike legacy background screening companies that store millions of unencrypted PDF resumes and tax IDs in vulnerable central databases, People Index never stores credentials. We cryptographically route trust between the issuer and assessor in real time.

02 // Mathematical Immutability

Cryptographic Ed25519 Signatures

Every credential issued across our exchange is digitally signed by assessed enterprise authorities using Ed25519 public-key cryptography. Tampering is mathematically impossible without invalidating the cryptographic proof.

03 // Selective Disclosure

Zero-Knowledge Proofs (ZKP)

Candidates can prove qualifications (such as holding a degree, earning over a salary threshold, or possessing active security clearance) without revealing sensitive underlying raw data.

04 // Granular Access Scopes

Explicit User Consent Engine

No employer or assessor can query an employee record without an active, time-bounded, cryptographic consent token approved by the individual from their identity wallet.

DATA PRIVACY & INFRASTRUCTURE

Authorized Sub-Processors

We maintain strict sub-processor governance. All service providers are evaluated for SOC 2 Type II compliance and ISO 27001 certification.

Sub-ProcessorPurpose / ServiceEntity Location
Amazon Web Services (AWS)Stateless Edge Compute & KMSGlobal / Multi-Region
CloudflareDDoS Mitigation, WAF & DNSSECGlobal Edge Network
DatadogEncrypted Telemetry & Real-Time Threat MonitoringUS / EU Isolated

Enterprise Security Review

Need our full SOC 2 Type II report, penetration testing executive summary, or standard SIG/CAIQ security questionnaire for your procurement team?

Vulnerability Disclosure Program

We believe in responsible disclosure and welcome feedback from security researchers. If you discover a potential vulnerability, please report it immediately to our security response team.