Snapshot 35909
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security and privacy are not a feature. They’re our identity. We take the responsibility of helping you manage your customer data seriously. That’s why security and privacy are key considerations in how we design and build our products. CCPA Data PrivacyFramework Program AICPA SOC 2 Type II ISO 27001 Kantara (NIST SP 800-63) HIPAA FERPA Age CheckCertification Scheme KJM iBeta Security and privacy by design Trust is built on security and privacy. That’s why Persona aligns its security and privacy practices with recognized industry standards, maintaining compliance and certifications to safeguard you and your customers. Certifications and compliance Our security and privacy frameworks are based on and aligned with global standards designed to support robust security and data protection practices. Please reach out to your Persona account manager or [email protected] for a copy of our certifications. Security Persona gives organizations granular control over every stage of the data life cycle, from customer-controlled retention to field-level redaction, dedicated isolated environments, and automated-by-default processing. Availability Our backup and replication program ensures data availability across primary and secondary systems. The Disaster Recovery program ensures that services remain available or are recoverable in case of disaster. Secure development We implement coding best practices focused on the OWASP Top Ten. Development, testing, and production environments are separated. Code changes are peer reviewed and tested prior to deployment, with post-incident review required within 48 hours for emergency changes. Continuous vulnerability scanning We maintain a comprehensive vulnerability management program which includes regular scanning, identification, and remediation of security vulnerabilities on infrastructure, endpoints, networks, and applications. Data encryption Verification processes that Persona runs are encrypted via HTTPS and TLS 1.2. Data in the database is encrypted using AES-256 encryption. Decryption keys are stored on separate hosts and rotated on a regular basis. Policies & training A comprehensive set of security policies and trainings is made available and shared with all personnel with access to Persona’s systems. Third party audits In addition to our extensive internal scanning and testing program, we employ third-party security experts to perform penetration tests. Logical access Access to production systems is restricted to necessary personnel, is audited and monitored, and is secured with multi-factor authentication. Internal controls All full-time employees undergo background checks and are administered security awareness training throughout their employment. Isolated environments Customer data is partitioned by organization and environment. For organizations with the most stringent requirements, Persona also offers dedicated environments sized to their workload and insulated from other customers’ traffic. Privacy Every decision we make begins with the safety and privacy of you and your customers' data in mind. Data transfer practices We perform transfers in a secure manner by encrypting data in transit. We are also able to support data residency in the US and the EU. Privacy policy Where we are required to provide a privacy policy, our privacy policy reflects the CCPA/CPRA and GDPR frameworks. We are transparent about how we collect and use your data. Privacy impact assessments We continuously evaluate the impact of our activities on data privacy to ensure that we collect the minimum data needed and improve our practices. No data brokering Personal data processed through Persona for verification is not sold, brokered to third parties, or used to train AI or machine learning models. We also provide secure methods to delete user data when required. Automated by default Verifications are processed by automated systems. When human review is enabled, it’s role-controlled and fully audited. Data controls Persona gives you granular control over how customer data is collected, retained, and deleted so your data practices can reflect your own compliance requirements and user commitments. Field-level redaction Permanently delete specific PII fields, like a government ID number or selfie image, while preserving the verification record. Remove only what you don’t need to keep, nothing more. Configurable retention policies Set automated deletion timelines by user population or data type. Data is removed on your schedule, not ours, and you can configure different policies for different segments of your user base. Data residency choice Choose between US and EU data centers. Your data is processed and stored in the region you select. Export and delete data via API Export or delete customer data programmatically via API or directly through the Persona dashboard to respond to data subject requests quickly and accurately. Role-based access control Granular, role-based permissions let you control who on your team can view or manage sensitive personal information. Access is scoped by role and environment, so exposure to PII is limited to the people whose responsibilities require it. Persona for Public Sector The Persona platform is a cloud-native comprehensive identity verification platform tool hosted on Google Cloud Platform (GCP) that's designed to help federal agencies verify their users' identities. The core capabilities of the Persona Platform are as follows: View on FedRAMP Marketplace Identity verification Persona offers multiple verification methods, including government ID verification (supporting over 200 countries and territories), selfie verification with biometric liveness detection, database verification, and NFC verification. Fraud prevention The platform offers device signals, passive signals (IP address, geolocation, device fingerprinting), and advanced algorithms to detect fraud vectors like deepfakes and spoofing. Compliance solutions Persona provides identity verification and screening solutions for agencies that need to meet global compliance requirements, including KYC (Know Your Customer), KYB (Know Your Business), and AML (Anti-Money Laundering). Customizable Workflows Agencies can create tailored verification journeys with drag-and-drop tools and custom rules. FedRAMP PMO and agencies can request access to our non-public FedRAMP materials by emailing [email protected] “As we deal with sensitive health records, we needed a certified identity solution that would help us verify patients quickly, accurately, and safely. Not only did Persona meet all of these expectations, but their NIST IAL certification will also play a key role in our ability to help patients get more out of their health records.” Deven McGraw Lead for Data Stewardship and Data Sharing at Citizen Health