Security & compliance
A background-verification company that can't prove its own controls is a contradiction.
Everything below is auditable, not just stated. The tamper-evident log that protects your candidates' data is the same one we built for our own case files — append-only, hash-chained, and verifiable end to end.
- INdata residency — Indian regions only
- TLSencrypted in transit, encrypted at rest
- 0silent edits — every change is logged
Every check dispatches at once. A slow registrar delays its own answer, never the case.
Edit a log entry. Watch the hash chain break.
This is not a demo — it is the same mechanism that protects every case on the platform. Change any value below and the integrity check will catch it.
Audit log · DPDP Act compliance test
5 entries · append-only hash chain
Candidate consent for 4 standard checks logged and cryptographically signed. DPDP Act compliance block initialized.
- Links back to
- genesis
- Seals as
- 8f3ac1d0
Offline XML matched against PAN record. Masked reference stored, discarding underlying PII according to data minimisation controls.
- Links back to
- 8f3ac1d0
- Seals as
- c47b9033
UAN mismatch found. Original and retrieved employer data attached as evidence payload.
- Links back to
- c47b9033
- Seals as
- 1d92e5b8
Candidate provided supplementary relieving letter to clear UAN discrepancy. Object stored in encrypted document storage.
- Links back to
- 1d92e5b8
- Seals as
- b6014fa5
Audit trail sealed. Signed URL issued and accessed. Viewer identity verified via SSO.
- Links back to
- b6014fa5
- Seals as
- 0ae773c6
Chain verified · 5 of 5 entries match
What we enforce, not what we intend.
Each control below is a thing the system does, not a policy a person is expected to follow. Open one to see how it works.
Encryption keys are held in a managed key service rather than in the application layer, so a compromised application server cannot read stored case data without the corresponding key. We share the specifics of our encryption and key management with customers on request.
Compute and storage run in Indian regions. Sub-processors that handle case data are documented and contractually bound to the same residency constraint. A change of sub-processor is a notifiable event, not a silent background decision.
Three role tiers — operations, hiring manager, approver — each see a different view of the same case. Every access event (open, view evidence, download report) is written to the case's audit trail with the user's identity and timestamp.
Retention is configurable per client, per check type. When the window closes, documents, extractions, and provenance events are deleted. The purge is a terminal event on the case's audit log — proof that data was held for the agreed period and then removed.
Under the DPDP Act, 2023, consent must be free, specific, informed, unconditional, and unambiguous. Papertrail captures it per check — not once for the entire case — with the exact wording shown, the device, and the OTP-verified signature stored as a discrete artefact.
Every event — consent given, check started, document uploaded, discrepancy raised, reviewer decision, report signed — is appended with a hash that chains to the previous entry. Altering any entry breaks the chain from that point forward, visibly and verifiably.
Certifications behind these controls
- NASSCOMIndustry association member
- ISO/IEC 27001Information security management
- ISO 9001:2015Quality management
- DSCIData Security Council of India
Encrypted
in transit and at rest
Keys held in a managed key service, not in the application layer.
100%
of case events written to the audit trail
Consent, uploads, extractions, reviews, verdicts, report generation, and purge — every one logged.
0
silent edits possible on a signed report
The content hash breaks on any change. Verification is a one-line command.
Hover over a figure to reveal the underlying capability
What the law requires and where it maps in the platform.
The Digital Personal Data Protection Act applies to every piece of candidate data Papertrail processes. These are not future intentions — they are implemented today.
A candidate's Aadhaar XML is used to verify identity. It is not used for marketing, analytics, or any secondary purpose. The purpose is captured in the consent artefact and governs the data's lifecycle.
A PAN check stores the PAN status and the name it is registered under. It does not store the candidate's full tax return, even if the document happens to contain one. The extraction is field-level, not document-level.
An erasure request is logged, evaluated against the retention policy, and executed if the window has not yet expired (in which case it is queued to execute at expiry). The erasure itself is logged as a terminal event.
The incident response process is documented, tested, and includes a notification step that fires within the timeframe the DPDP Act requires — not at the end of an investigation, but at the point of reasonable certainty.
Security & compliance, answered
The controls described on this page are built to the ISO 27001:2022 standard. Certification status is documented in the trust centre with the certificate number and scope — we do not claim it here without that reference.
In Indian cloud regions — compute and object storage both. Sub-processors that handle case data are contractually bound to the same residency requirement. The trust centre lists every sub-processor by name.
The reviewer's decision — confirm, dismiss, escalate — is logged as its own event in the case's audit trail, with the reviewer's identity, the timestamp, and the reasoning attached. The original AI signal is preserved alongside the override, not replaced by it.
The incident response process includes detection, containment, assessment, client notification within the statutory window, and a root-cause review. The notification step fires at the point of reasonable certainty, not at the end of the investigation.
Yes. The trust centre provides the documentation; a vendor-assessment questionnaire response is available on request; and for enterprise accounts, we support a guided review of the control set with your security or compliance team directly.
Review the controls
Walk through the security architecture with your team.
Bring your vendor assessment questionnaire. We will fill it live and show you the controls it asks about, running on a real case.