Trust & Security
How we approach access, audit, and consumer-data readiness — without overclaiming.
What we will say — and what we will not
People Vetting is aligning to FCRA CRA obligations and PBSA BSOAP US practices as we build. We do not claim PBSA accreditation, SOC 2 certification, or similar badges until they are earned and counsel-approved for public use.
Controls in place today
- Staff access with MFA (TOTP) before operational dashboards
- Append-only audit events for sensitive actions
- Role-based access and access-authorization checklist
- Security headers (CSP, nosniff, frame controls; HSTS on HTTPS)
- Cookie consent logging for analytics/marketing categories
- Live data purchases blocked until explicitly authorized
Data vendors
Third-party screening data is purchased only through our kernel. Provider integrations are prepared and gated; they are not live-linked for production consumer reports until compliance owners authorize them.
Local investigative services
Metro Risk Management Group also describes local investigative capacity (Miami / South Florida) separately from People Vetting consumer reporting. South Florida office: 20533 Biscayne Blvd, Suite 4-308, Aventura, FL 33180. See Miami local services. Florida professional licensing details are confirmed in writing before fieldwork; this site does not claim a license number until counsel-approved for public use.
Incidents
We maintain an incident response runbook and security incident records for staff use. Report suspected security issues to compliance@peoplevetting.com.