Security, data and limitations
The publicly stated design guarantees, exact scope of evidence and risks that do not disappear.
Security principles
- Device-bound keys: prefer non-exportable keys and platform attestation where available.
- Freshness: bind every operation to a nonce, expiry and active event.
- Least privilege: limit tokens, roles and resources to the required tenant and purpose.
- Explicit degradation: a missing or insufficient dependency never produces silent success.
- Revocation: check device status before sensitive operations and invalidate sessions quickly.
- Traceability: attribute, version and log critical changes.
- Resilience: use pre-approved alternatives without lowering the requested level.
Data protection
| Data | Public principle |
|---|---|
| Biometrics | The template remains managed by iOS or Android; Easytiou receives only a local-authentication result. |
| Contact details | Normalisation, encryption and isolated lookup; no account-existence disclosure before acceptance. |
| Evidence | Content limited to necessary facts, with retention and access policies. |
| SIEM alerts | Pseudonymisation and exclusion of secrets, raw media and biometric data. |
| Administration | Tenant isolation and logging of sensitive access. |
Retention periods, processing regions and legal bases will be specified in contractual documents and the privacy policy for each offering.
What the solution does not prove
The service does not certify that an image or voice is natural, that a statement is true or that a person’s intent is genuine.
- An attacker may relay an interaction in real time; controls aim to increase cost and detectability.
- Participants holding legitimate devices may collude.
- The genuine holder may act under manipulation, urgency or duress.
- An already compromised legitimate device may produce a valid signature.
- An external provider may be unavailable or compromised.
- Meeting content and external consequences remain outside the core evidence scope.
Complementary controls
For irreversible decisions, Easytiou remains one control among others. The organisation must maintain procedures proportionate to its risks.
- Separation of duties and dual approval.
- Callback through a known independent channel.
- Cooling-off period before unusual payments.
- Payment limits, beneficiary allowlists and banking controls.
- Incident procedure for coercion or compromise.
Responsible disclosure
A vulnerability-reporting channel and disclosure policy will be published before service launch. Until then, this documentation must not be interpreted as permission to test third-party systems or Easytiou environments without written authorisation.
The project is at specification and prototype stage. No production availability, certification or measured resistance is claimed today.
Try “data”, “device” or “limitations”.
