Back to Home

Information Security Policy

Published: April 7, 2026

Download PDF

1. Purpose

This Information Security Policy establishes the security principles, controls, and practices that PersonaBlocks ("we," "us," or "our") implements to protect user data, platform infrastructure, and identity verification services. This policy applies to all systems, employees, contractors, and third-party partners involved in the operation of the PersonaBlocks platform.

2. Scope

This policy covers:

3. Security Architecture

3.1 Sovereign Encryption Model

PersonaBlocks employs a client-side encryption architecture where users retain sole control of their identity data:

3.2 Data Classification

4. Access Controls

4.1 Authentication

4.2 Authorization

5. Infrastructure Security

5.1 Transport Security

5.2 Application Security

5.3 Blockchain Security

6. Data Protection

6.1 Encryption at Rest

6.2 Encryption in Transit

6.3 Digital Watermarking & Forensics

7. Compliance & Regulatory

7.1 Sanctions Screening

7.2 Audit Logging

7.3 Utah S.B. 275 Compliance

PersonaBlocks is designed to comply with Utah Senate Bill 275 (effective May 6, 2026), which mandates:

8. Incident Response

8.1 Detection

8.2 Response Procedures

8.3 Customer Protections

Because PersonaBlocks uses client-side encryption, a server compromise does not expose user identity documents. An attacker who gains server access would only obtain encrypted blobs that require the user's wallet private key to decrypt.

9. Third-Party Security

10. Physical Security

11. Business Continuity

12. Policy Updates

This Information Security Policy is reviewed and updated at least annually, or whenever significant changes are made to platform architecture, compliance requirements, or threat landscape. Material changes will be communicated through the PersonaBlocks website.

13. Contact

For security concerns, vulnerability reports, or questions about this policy, contact us at:

PersonaBlocks

Email: privacy@personablocks.io

Website: https://www.personablocks.io