Security, Privacy & Evidence Protection
Trust starts with protected original evidence.
Immutable Originals · RBAC · Audit · Reference Vault
Security is designed around tenant isolation, immutable raw evidence, restricted reference intelligence, audited privileged access and a clear separation between customer evidence and crown-jewel reference assets.
Trust architectureProtected by layer
1Upload edgeContent sniffing · hash · malware quarantine
Untrusted input 2Immutable evidenceOriginal bytes + derivative lineage
Restricted 3ProcessingOCR · quality · source · forensics
Derived only 4Decision & reviewReason codes + human adverse gate
Controlled 5Audit & receiptTraceable evidence without exposing reference internals
Auditable
Source-firstAuthoritative routes outrank appearanceMinimum evidenceEscalate only what can resolve uncertaintyHuman gateSerious adverse outcomes require reviewAuditableMaterial actions preserve lineage
WHAT BONAFIDE DOES
Purpose-built verification capabilities.
Each capability is a visible part of the verification workflow—not a hidden AI score.
◇Encryption & secrets
Encryption in transit/at rest, environment-separated secrets/key management and short-lived signed evidence URLs.
✓Tenant controls
Tenant-scoped RBAC, tested row-level/authorization boundaries and MFA for privileged/admin/reviewer roles.
◎Evidence access audit
Raw documents and restricted reference-profile reads are logged.
↗Reference Intelligence Vault
Separate storage namespace/key policy, no customer bulk export and elevated approval for sensitive exports.
▦Privacy engineering
Purpose/consent, retention/deletion, PII-minimized logs, vendor/subprocessor inventory and data-location assessment.
⌁Secure SDLC
SAST/dependency/container scanning, incident response and independent application/security assessment before serious production use.
EVIDENCE MODELReference profiles are treated as crown-jewel data.
Public results can explain the evidence category and reason code without exposing precise template geometry, character fingerprints or security-region details that could help an attacker improve a forgery.
- No raw cross-tenant credential correlation in V1
- Privacy-safe cross-tenant signals remain disabled until legal-reviewed design supports a legitimate purpose
- Independent penetration/application review is required before serious production use
- ISO/IEC 27001 and SOC 2 are assurance-roadmap milestones—not premature marketing claims
TRUST ZONESLeast privilege by boundary
EEvidence zoneImmutable originals and source snapshots
Restricted IIntelligence zoneRegistry + provenance + approvals
Controlled RReference vaultProfiles and genuine corpora
Crown-jewel AAdmin & complianceRights, retention, legal hold, access audit
MFA/RBAC
WORKFLOW
From input to defensible evidence.
Bonafide follows the strongest available verification route and resumes only the affected lane when new evidence arrives.
01Authenticate→
02Authorize tenant/role→
03Access immutable evidence→
04Audit every material action→
05Apply retention/rights policy
DESIGNED FOR
One evidence model. Role-specific operations.
The same underlying case can be viewed differently by institutions, employers, reviewers, operations and candidates.
01Enterprise security teams
Review controls and trust boundaries
02Institution admins
Role and evidence governance
03DCS internal operators
Restricted vault and privileged workflows
DECISION DISCIPLINEUnknown ≠ fake.
Unmapped issuer, new template, legacy document or unavailable source must route to uncertainty/manual verification rather than an automatic accusation.
Authority VerifiedAuthoritative source evidence is consistent.Highly ConsistentStrong supporting evidence; independent source not complete.Evidence RequiredA targeted item can likely resolve the case.Unable to DetermineEvidence remains insufficient; no fraud conclusion.
DCS BONAFIDE · CREDENTIAL INTELLIGENCE PLATFORM
Establish what is bona fide.
Preserve the evidence.