It is imperative that our technology not only meet our customers’ needs but also ensure their privacy and safety. We take your trust in us very seriously and design our software to protect and securely store personal data. “We help keep identities safe by making sure only our customers see and use the data to which they are legally entitled.”
All data is collected, transacted and stored within the ZipID secure environment. Each customer has its own secure folder, as does each individual Form I-9. ZipID requires data and images be captured and held for varying time frames, depending on federal law and the customer’s use case. In accord with federal law, all captured data is retained or purged on a scheduled basis. All new data is held for 30 days online, with data more than 30 days old retained offline for additional security but available to customers upon request.
All customers and employees must actively opt in. Any Customer may request a purge or return of data immediately and at any time upon request. All Employees may download and retain their transaction upon conclusion and approval of sending their information to the customer (employer). All users must explicitly opt in to our workflow prior to beginning the Form I-9 workflow.
ZipID uses Amazon Web Services and embedded security products within their trusted ecosystem to host and deploy our applications using containers run on AWS managed services. We are SOC 2 Type 1 compliant, meaning we are evaluated to assure that our security controls are designed for security against unauthorized access, breaches and cyber threats; systems are available and accessible as needed; data processing is accurate and reliable; sensitive information is kept confidential; and personal information remains private.
ZipID performs ongoing third-party penetration tests from trusted security vendors during both development and post-deployment of our product. All activity is made within ZipID’s cloud server. Assuring personal data never leaves the ZipID cloud server minimizes the possibility of information being intercepted or hacked. Additionally, all data is encrypted at industry standard levels at rest and in transit within our instance.
All personally identifiable information (PII) is directly provided by the customer or new hire within ZipID’s secure portal. Only PII required to complete the Form I-9 for that employee is captured as required by federal law. ZipID only captures and stores PII for the stated federal law requirements and to assure user identity within the use of our products, always minimizing exposure of customer and employee data. This data is never sold, transferred, or otherwise used for any third-party purpose aside from our core products or partner integrations.
GlideCraft is your ultimate integration solution, seamlessly connecting all your essential tools and platforms into one.
ZipID’s highly accurate AI-based optical reader technology assures that ID information extracted for the purpose of Form I-9 autofill creates confidence that data in each Form I-9 field is accurate. Even with use of OCR technologies, ZipID provides an extra layer of accuracy, enabling employees and customers to check extracted data and make “tracked” changes as need be. In addition, in the background, our OCR is checking and verifying IDs against fraud. While ZipID does not guarantee that our OCR will detect fraud on every submitted ID, we have great confidence that the OCR is providing useful information to employers to augment legal authorization determinations of their new hires.
We use mathematical representations of faces instead of actual photos to produce matching “confidence scores" that the new hire is who they say they are. No third party has access to ID images or photos. In addition, all data is encrypted at rest and in transit to keep identities safe, even if our AWS infrastructure is compromised. ZipID algorithms are developed and optimized to assure accuracy. Our recent algorithms submitted to the National Institute of Science and Technology (NIST), viewed as the industry gold standard, show that ZipID has a 99.998% accuracy rate and is top 6 for accuracy of matched decisions in the U.S. as of March 2025.