Skip to content

Security & compliance

A background-verification company that can't prove its own controls is a contradiction.

Everything below is auditable, not just stated. The tamper-evident log that protects your candidates' data is the same one we built for our own case files — append-only, hash-chained, and verifiable end to end.

  • INdata residency — Indian regions only
  • TLSencrypted in transit, encrypted at rest
  • 0silent edits — every change is logged
case/PT-24817/dispatch0/4 answered
Papertrail core
Court recordsNo case foundquerying…
Credit bureauNo defaultquerying…
University registrarSerial matchedquerying…
Global watchlists0 of 214 hitquerying…

Every check dispatches at once. A slow registrar delays its own answer, never the case.

Try it yourself

Edit a log entry. Watch the hash chain break.

This is not a demo — it is the same mechanism that protects every case on the platform. Change any value below and the integrity check will catch it.

case/PT-24817/audit-log
Live

Audit log · DPDP Act compliance test

5 entries · append-only hash chain

100%
Intact
  • Candidate consent for 4 standard checks logged and cryptographically signed. DPDP Act compliance block initialized.

    Links back to
    genesis
    Seals as
    8f3ac1d0
  • Offline XML matched against PAN record. Masked reference stored, discarding underlying PII according to data minimisation controls.

    Links back to
    8f3ac1d0
    Seals as
    c47b9033
  • UAN mismatch found. Original and retrieved employer data attached as evidence payload.

    Links back to
    c47b9033
    Seals as
    1d92e5b8
  • Candidate provided supplementary relieving letter to clear UAN discrepancy. Object stored in encrypted document storage.

    Links back to
    1d92e5b8
    Seals as
    b6014fa5
  • Audit trail sealed. Signed URL issued and accessed. Viewer identity verified via SSO.

    Links back to
    b6014fa5
    Seals as
    0ae773c6

Chain verified · 5 of 5 entries match

Controls

What we enforce, not what we intend.

Each control below is a thing the system does, not a policy a person is expected to follow. Open one to see how it works.

  • Encryption keys are held in a managed key service rather than in the application layer, so a compromised application server cannot read stored case data without the corresponding key. We share the specifics of our encryption and key management with customers on request.

  • Compute and storage run in Indian regions. Sub-processors that handle case data are documented and contractually bound to the same residency constraint. A change of sub-processor is a notifiable event, not a silent background decision.

  • Three role tiers — operations, hiring manager, approver — each see a different view of the same case. Every access event (open, view evidence, download report) is written to the case's audit trail with the user's identity and timestamp.

  • Retention is configurable per client, per check type. When the window closes, documents, extractions, and provenance events are deleted. The purge is a terminal event on the case's audit log — proof that data was held for the agreed period and then removed.

  • Every event — consent given, check started, document uploaded, discrepancy raised, reviewer decision, report signed — is appended with a hash that chains to the previous entry. Altering any entry breaks the chain from that point forward, visibly and verifiably.

Certifications behind these controls

  • NASSCOMIndustry association member
  • ISO/IEC 27001Information security management
  • ISO 9001:2015Quality management
  • DSCIData Security Council of India

Encrypted

in transit and at rest

Keys held in a managed key service, not in the application layer.

100%

of case events written to the audit trail

Consent, uploads, extractions, reviews, verdicts, report generation, and purge — every one logged.

0

silent edits possible on a signed report

The content hash breaks on any change. Verification is a one-line command.

Hover over a figure to reveal the underlying capability

DPDP Act, 2023

What the law requires and where it maps in the platform.

The Digital Personal Data Protection Act applies to every piece of candidate data Papertrail processes. These are not future intentions — they are implemented today.

  • A candidate's Aadhaar XML is used to verify identity. It is not used for marketing, analytics, or any secondary purpose. The purpose is captured in the consent artefact and governs the data's lifecycle.

  • A PAN check stores the PAN status and the name it is registered under. It does not store the candidate's full tax return, even if the document happens to contain one. The extraction is field-level, not document-level.

  • An erasure request is logged, evaluated against the retention policy, and executed if the window has not yet expired (in which case it is queued to execute at expiry). The erasure itself is logged as a terminal event.

  • The incident response process is documented, tested, and includes a notification step that fires within the timeframe the DPDP Act requires — not at the end of an investigation, but at the point of reasonable certainty.

FAQ

Security & compliance, answered

  • The controls described on this page are built to the ISO 27001:2022 standard. Certification status is documented in the trust centre with the certificate number and scope — we do not claim it here without that reference.

  • In Indian cloud regions — compute and object storage both. Sub-processors that handle case data are contractually bound to the same residency requirement. The trust centre lists every sub-processor by name.

  • The reviewer's decision — confirm, dismiss, escalate — is logged as its own event in the case's audit trail, with the reviewer's identity, the timestamp, and the reasoning attached. The original AI signal is preserved alongside the override, not replaced by it.

  • The incident response process includes detection, containment, assessment, client notification within the statutory window, and a root-cause review. The notification step fires at the point of reasonable certainty, not at the end of the investigation.

  • Yes. The trust centre provides the documentation; a vendor-assessment questionnaire response is available on request; and for enterprise accounts, we support a guided review of the control set with your security or compliance team directly.

Review the controls

Walk through the security architecture with your team.

Bring your vendor assessment questionnaire. We will fill it live and show you the controls it asks about, running on a real case.