Hacker News new | ask | show | jobs
by rswail 102 days ago
Looks like an awesome launch.

Given all the privacy breaches already in this space, what auditing are you planning to ensure that PII is not held anywhere in the stack after KYC/AML/ID confirmation?

This goes beyond ISO27K/HIPAA/SOC2 etc to an actual code/storage audit that confirms that PII is only held ephemerally and completely encrypted at rest otherwise, unavailable to anyone, including internal access and/or law enforcement etc.