Data Security Standards
How screening data and sealed certificates are protected, from encryption to incident response.
1. Encryption
Data is encrypted in transit (TLS) and at rest, using FIPS 140-3 validated cryptographic modules. Every certificate's SHA-256 seal is computed server-side before the result is ever shown, so the seal itself is never exposed to tampering between screening and sealing.
2. Zero-Trust Access
Every screening request passes through a Zero-Trust Gateway with no human override capability — no team member can bypass a registry check or alter a result before it's sealed. Internal access to production systems is role-based and logged.
3. Key Management & Access Reviews
API keys and credentials for the government data sources EasyWorth connects to (Trade.gov, SAM.gov, FMCSA, DHS) are stored as server-side secrets, never exposed to the client or logged in request URLs. Access to production infrastructure is reviewed periodically and revoked when no longer needed.
4. Incident Response & Breach Notification
If a security incident affects your data, we will notify affected clients without undue delay after confirming the scope of the incident, consistent with applicable breach notification law. Sealed certificates are tamper-evident by design — any unauthorized alteration to a ledger entry is independently detectable by anyone who verifies its hash at ledger.easyworth.net.
EasyWorth, Inc. — Charlotte, NC