Last updated: 2026-08-20

Is it safe to put clients' passports and NRICs into cloud software?

In CorpSec AI every document and uploaded file is locked in its own encrypted envelope before it is saved, with a key that is not kept in the database — so a stolen database is unreadable. The concern is reasonable, and the honest way to answer it is to say exactly what happens to the file. When a document or scanned ID enters CorpSec AI, it is sealed in its own individual encrypted envelope before it is written to storage. Each file gets a unique, single-use key; that key is then locked with a key belonging only to your firm; and your firm's key is derived from a master key held outside the database entirely. Someone who obtained a full copy of the database and the file store would hold scrambled bytes, not a passport. The envelope is also bound to your firm and to that file's own fingerprint, so a sealed file lifted into another firm's account will not open. If the key is ever unavailable, the system refuses to save the file rather than storing it unprotected. It is also worth comparing against the real alternative: identity documents arriving by WhatsApp and sitting in a laptop folder are unencrypted, uncontrolled, and leave no record of who opened them.
WhatsApp
Get a free consultation
E&H
Business Consultant
Lynn
Online
WhatsApp