Trust & safety
Checkify is designed to minimise unnecessary identity-data exposure, using device-first and privacy-minimising processing where supported so businesses can receive the proof they need without automatically becoming custodians of underlying identity documents.
本页从高层次描述了我们的安全方法。确切的控制可能因部署和集成要求而异。
默认证明(例如“超过18岁”)而不是原始个人数据。用户必须明确同意任何数据共享。
设备绑定身份、生物识别/PIN 保护和有时限的令牌可降低帐户接管和重放风险。
跨设备存储、加密、传输安全、服务器保护和可审核性的分层控制。
专为隐私优先验证而构建
过期请求、服务器验证和签名有效负载会降低复制/转发代码的价值。
设备绑定身份 + 生物识别/PIN 检查 + 短期令牌有助于防止未经授权的访问。
证明优先流程和明确同意可减少将敏感数据存储在不需要的地方的可能性。
Checkify is designed around device-first and privacy-minimising processing where supported. Where server-side data is required for operational reasons (for example audit events or request references), we minimise personal data and focus on proofs and metadata.
可以——企业可以请求特定的证据,如果需要,还可以请求特定的数据点。用户会审查每个请求,并且在共享任何内容之前必须明确同意。
请求和响应被设计为可加密验证、有时间限制并由接收者验证。这使得篡改可被检测到并降低重放价值。
如果您认为自己发现了安全漏洞,请负责任地报告。我们将及时审核报告,并与您一起验证和修复问题。
Email the security team with enough detail to reproduce the issue. For privacy questions, see the Privacy Policy.