Platform Security

Encryption-First Architecture &
Tamper-Evident Audit Trail

Every candidate background scan and history holding is secured at rest and in transit, with every access logged in an append-only audit trail.

Encryption at Rest & in Transit
Protecting sensitive identifiers end to end.

Candidate identifiers (PAN, Aadhaar) are encrypted at rest and only ever decrypted server-side for an authorized, consented search.

  • TLS in transit, encryption at rest
  • Salted, irreversible password hashing
  • Aligned with Indian IT Act Section 43A
Full Audit Trail
Every action, traceable.

Every login, record creation, search, and flag change is written to an append-only audit log reviewable by Compliance.

  • Consent tracked on every registry search
  • Role-based access control per portal
  • Exportable compliance reports
audit-log-sample.logVERIFIED

[AUDIT] registry.searched — actor: hr@checkbokx.in — target: rec_priya

[AUDIT] verification_case.completed — resultingFlag: red

[AUDIT] Status: LOGGED ✓