How Passify handles data and what security controls are implemented.
Passify never stores, processes, or transmits personal identity data. The architecture is deliberately minimal:
┌─────────────┐ ┌──────────────┐ ┌─────────────┐
│ Investor │────▶│ KYC Provider │────▶│ Provider │
│ (browser) │ │ (Blockpass) │ │ Database │
└─────────────┘ └──────┬───────┘ └─────────────┘
│ webhook (approved/rejected)
▼
┌──────────────┐ ┌─────────────┐
│ Passify │────▶│ Solana │
│ (server) │ │ (on-chain) │
└──────────────┘ └─────────────┘
│
Stores ONLY:
• SHA-256 hash of KYC result
• Solana public key
• Attestation metadata
• Expiration timestampWe store
We never store
Passify is designed to support platforms subject to AML/KYC requirements without becoming a regulated entity itself. We do not process or store PII — the KYC provider (e.g., Blockpass) handles identity verification and data retention. Passify acts as an attestation layer, recording only the cryptographic proof that verification occurred.
This architecture means platforms using Passify do not need to store or process investor PII directly.
For security inquiries, vulnerability reports, or compliance questionnaires: security@passify.biz