Skip to content

Trust & Security

How we approach access, audit, and consumer-data readiness — without overclaiming.

What we will say — and what we will not

People Vetting is aligning to FCRA CRA obligations and PBSA BSOAP US practices as we build. We do not claim PBSA accreditation, SOC 2 certification, or similar badges until they are earned and counsel-approved for public use.

Controls in place today

  • Staff access with MFA (TOTP) before operational dashboards
  • Append-only audit events for sensitive actions
  • Role-based access and access-authorization checklist
  • Security headers (CSP, nosniff, frame controls; HSTS on HTTPS)
  • Cookie consent logging for analytics/marketing categories
  • Live data purchases blocked until explicitly authorized

Data vendors

Third-party screening data is purchased only through our kernel. Provider integrations are prepared and gated; they are not live-linked for production consumer reports until compliance owners authorize them.

Local investigative services

Metro Risk Management Group also describes local investigative capacity (Miami / South Florida) separately from People Vetting consumer reporting. South Florida office: 20533 Biscayne Blvd, Suite 4-308, Aventura, FL 33180. See Miami local services. Florida professional licensing details are confirmed in writing before fieldwork; this site does not claim a license number until counsel-approved for public use.

Incidents

We maintain an incident response runbook and security incident records for staff use. Report suspected security issues to compliance@peoplevetting.com.

Draft page — counsel and InfoSec owners must approve production wording.