Evidence before claims.
PeopleScore separates source implementation, deployment verification and independent assurance. A control is not represented as certified merely because code or configuration exists.
Implemented in source
Database-per-tenant routing, forced tenant RLS, relationship-aware authorization, MFA controls, durable payment webhook intake, worker fencing, private object-storage/KMS adapter, secure upload re-encoding and fail-closed launch gates.
Requires deployment evidence
Managed HA databases, PITR and restore drills, multi-zone replicas, operated telemetry/alerts, provider-backed email and payments, private bucket policy, KMS grants, external scans and incident/on-call operation.
Requires independent approval
Penetration testing, PCI scope/attestation, legal and privacy documents, employment-AI assessment, WCAG manual audit, provider KYC, live-money proof and jurisdiction launch approval.
Not currently claimed
SOC 2 certification, ISO 27001 certification, contractual availability, global regulatory coverage, or market superiority. These require independent and operating evidence.
Responsible disclosure
The canonical reporting instructions and safe-testing boundaries are published on the security page. Sensitive reports must never be submitted through commercial forms.
View disclosure policy