Trust is our protocol.
Security is our foundation.
We eliminate enterprise hiring liability by removing centralized data storage entirely. Explore our compliance certifications, security architecture, and independent audit reports.
Continuous compliance assessed by independent auditors.
We adhere to strict international regulatory frameworks and undergo recurring third-party audits.
SOC 2 Type II
Independently audited by top-tier CPA firms assessing security, availability, and strict confidentiality controls.
ISO/IEC 27001
International gold standard for Information Security Management Systems covering infrastructure, personnel, and operations.
GDPR & CCPA
User-directed data exchange. No centralized credential storage or persistent profiling without explicit cryptographic consent.
W3C DID & VC Native
Built natively on W3C Decentralized Identifiers and Verifiable Credentials, guaranteeing cross-border enterprise interoperability.
DPDP & Global Privacy
Engineered to comply with the Indian DPDP Act, Singapore PDPA, and global data residency requirements.
Zero-Storage Protocol
PIX is a stateless trust intelligence router. Credentials are never stored on our servers, eliminating mass data breach liabilities.
Security engineered into every packet.
Traditional platforms protect databases with firewalls. People Index solves security by ensuring there is no database to breach.
Zero Centralized Storage
Unlike legacy background screening companies that store millions of unencrypted PDF resumes and tax IDs in vulnerable central databases, People Index never stores credentials. We cryptographically route trust between the issuer and assessor in real time.
Cryptographic Ed25519 Signatures
Every credential issued across our exchange is digitally signed by assessed enterprise authorities using Ed25519 public-key cryptography. Tampering is mathematically impossible without invalidating the cryptographic proof.
Zero-Knowledge Proofs (ZKP)
Candidates can prove qualifications (such as holding a degree, earning over a salary threshold, or possessing active security clearance) without revealing sensitive underlying raw data.
Explicit User Consent Engine
No employer or assessor can query an employee record without an active, time-bounded, cryptographic consent token approved by the individual from their identity wallet.
Authorized Sub-Processors
We maintain strict sub-processor governance. All service providers are evaluated for SOC 2 Type II compliance and ISO 27001 certification.
| Sub-Processor | Purpose / Service | Entity Location |
|---|---|---|
| Amazon Web Services (AWS) | Stateless Edge Compute & KMS | Global / Multi-Region |
| Cloudflare | DDoS Mitigation, WAF & DNSSEC | Global Edge Network |
| Datadog | Encrypted Telemetry & Real-Time Threat Monitoring | US / EU Isolated |
Enterprise Security Review
Need our full SOC 2 Type II report, penetration testing executive summary, or standard SIG/CAIQ security questionnaire for your procurement team?
Vulnerability Disclosure Program
We believe in responsible disclosure and welcome feedback from security researchers. If you discover a potential vulnerability, please report it immediately to our security response team.