Documents are encrypted in transit and at rest.
Security overview
Security is the precondition.
Veteran Passport™ handles sensitive service documents. Security is a precondition of the product, not a feature of it.
Our practices
Access to veteran documents is limited by role and operational necessity.
Veteran consent is captured and retained as a record.
Access and verification events are logged.
We extract only what verification and approved services require.
A formal independent assurance framework is under evaluation.
What we do not do
We do not sell veteran personal information. We do not share DD-214 contents, disability information, discharge characterization, or contact information with third parties for their own commercial purposes.
Reporting a vulnerability
Please report suspected vulnerabilities to contact@jptidentity.com with “Security report” in the subject line. Please do not include sensitive veteran information in an initial report. We will acknowledge receipt and coordinate next steps.
Responsible disclosure
We ask security researchers to act in good faith, avoid accessing or altering personal data, avoid disrupting service, and give us reasonable time to investigate before public disclosure. This statement does not authorize access that would otherwise be unlawful.

