Security at sii{me}
The safeguards protecting account access, identity status, private Passports, hiring activity, billing references, and operational evidence.
Access and isolation
Authenticated roles, server-owned transitions, row-level database policies, least-privilege service credentials, protected admin actions, private-by-default identity, and mutual-consent gates limit who can see or change hiring information.
Provider boundaries
Persona handles government-ID and live-selfie media. Stripe handles bank and card credentials. sii{me} retains provider references, verification or payment status, signed agreement receipts, and the minimum operational data needed to run the service.
Application controls
Signed webhooks, idempotency records, input validation, rate limits, immutable attribution snapshots, structured audit events, protected approval links, and server-side authorization guard high-impact actions.
Operational readiness
Production launch requires environment preflight, backup and restoration validation, dependency review, incident response ownership, error monitoring, availability checks, and post-deployment scans. Security concerns may be reported to security@siime.ai.