Platform Security
Encryption-First Architecture &
Tamper-Evident Audit Trail
Every candidate background scan and history holding is secured at rest and in transit, with every access logged in an append-only audit trail.
Encryption at Rest & in Transit
Protecting sensitive identifiers end to end.
Candidate identifiers (PAN, Aadhaar) are encrypted at rest and only ever decrypted server-side for an authorized, consented search.
- TLS in transit, encryption at rest
- Salted, irreversible password hashing
- Aligned with Indian IT Act Section 43A
Full Audit Trail
Every action, traceable.
Every login, record creation, search, and flag change is written to an append-only audit log reviewable by Compliance.
- Consent tracked on every registry search
- Role-based access control per portal
- Exportable compliance reports
audit-log-sample.logVERIFIED
[AUDIT] registry.searched — actor: hr@checkbokx.in — target: rec_priya
[AUDIT] verification_case.completed — resultingFlag: red
[AUDIT] Status: LOGGED ✓