Security & Trust Statement (postal.ID)

This page summarizes security practices at a high level for customer procurement. It is not a contract. Contractual commitments are in the Security Addendum / DPA.

1

1. Security principles

  • Least privilege access and role-based access control.
  • Encryption in transit and at rest for sensitive data.
  • Audit logging and tamper-evident evidence artifacts.
  • Vendor risk management for subprocessors.
  • Incident response and breach notification processes.
2

2. Data segregation

Verification subject data is segregated per tenant. No cross-customer reuse of verification subject results.

3

3. Evidence integrity

Evidence packs may include cryptographic hashes and event logs designed to detect tampering.

4

4. Responsible disclosure

Report security issues to [SECURITY@POSTAL.ID].