Security & Trust Statement (postal.ID)
This page summarizes security practices at a high level for customer procurement. It is not a contract. Contractual commitments are in the Security Addendum / DPA.
1. Security principles
- Least privilege access and role-based access control.
- Encryption in transit and at rest for sensitive data.
- Audit logging and tamper-evident evidence artifacts.
- Vendor risk management for subprocessors.
- Incident response and breach notification processes.
2. Data segregation
Verification subject data is segregated per tenant. No cross-customer reuse of verification subject results.
3. Evidence integrity
Evidence packs may include cryptographic hashes and event logs designed to detect tampering.
4. Responsible disclosure
Report security issues to [SECURITY@POSTAL.ID].