Security & Compliance

Security at Every Layer

PhysicalGuard is engineered from the ground up with defense-in-depth principles. Every biometric template, every audit log, every API call is protected.

Defense in Depth

Security Features

Multiple layers of protection ensure that biometric data, audit trails, and system access are secured at every level.

AES-256-GCM Encryption

All biometric templates are encrypted with AES-256-GCM authenticated encryption. Unique nonces per record prevent replay attacks.

Zero Plaintext Storage

Biometric data never exists in plaintext on disk. Templates are encrypted before writing and decrypted only in secure memory during matching.

Tamper-Evident Audit Chain

Every audit log entry includes an HMAC hash linking it to the previous entry. Any modification breaks the chain and is immediately detectable.

Anti-Spoofing Liveness

Built-in liveness detection algorithms prevent presentation attacks — rubber fingerprints, printed irises, and digital replay attempts are rejected.

Auto-Lockout

Accounts are automatically locked after configurable failed authentication attempts. Administrators are alerted immediately via the admin portal and SIEM.

Rate Limiting

Per-client and per-endpoint rate limiting protects the API from brute-force and denial-of-service attempts. Configurable thresholds and lockout durations.

Regulatory Readiness

Compliance Built In

PhysicalGuard is designed to help organisations meet the most demanding regulatory requirements across multiple industries and geographies.

SOX Compliance

Sarbanes-Oxley Act

Tamper-proof audit trails, segregation of duties via role-based access, and complete change tracking satisfy SOX Section 404 internal control requirements.

PCI-DSS

Payment Card Industry

Multi-factor biometric authentication, encrypted data at rest and in transit, access logging, and network segmentation support align with PCI-DSS requirements.

HIPAA

Health Insurance Portability

Unique user identification, automatic logoff, encryption, and audit controls satisfy HIPAA Technical Safeguards for electronic protected health information (ePHI) access.

GDPR

General Data Protection Regulation

Biometric data processed under explicit consent with purpose limitation. Data minimisation, encryption, and the right to erasure are supported by design.

DPDP Act

Digital Personal Data Protection (India)

Compliant with India's DPDP Act 2023 — explicit consent for biometric data processing, purpose limitation, data localisation support, breach notification readiness, and Data Fiduciary obligations built into the platform.

Audit

Comprehensive Audit Infrastructure

PhysicalGuard's audit system goes beyond simple logging. Every event is part of a cryptographic chain that can be independently verified for integrity.

  • 7-year configurable log retention
  • Audit-of-audit logging (who viewed audit logs)
  • One-click integrity verification from the admin portal
  • Real-time anomaly alerting with configurable rules
  • SIEM forwarding with event-type filtering
  • Exportable reports for auditors and regulators
Encrypted Verified Audited

Security You Can Verify

Request a security deep-dive with our team. We'll walk you through our encryption, audit chain, and compliance controls in detail.