What the email link doesOpens one person's part of one request.
- The account holder and representative receive different links
- Each link works once and expires
- A fresh link turns every earlier link for that person off
- Each person sees only the steps assigned to their role
What the email link does not doIt is not identity verification.
- It does not prove the person's legal identity
- It does not validate the power of attorney document
- It does not approve the representative
- It does not grant account credentials or permission to move money
Built into each requestControls available today
- Only authorized institution users or people with a current role-bound link can act
- Every saved change is added to the activity history
- Repeated submissions do not create duplicate actions
- Failed email and system deliveries can be reviewed and retried
Required before a production pilotAssurance still in progress
- Production identity and organization-isolation review
- Encryption and key-management review
- Retention, deletion, backup, and recovery testing
- Independent security assessment and penetration test
- Vendor, incident, privacy, and legal reviews
Before a pilot with approved customer data, the institution and Passage must agree exactly how identity will be checked and complete the required security, legal, fraud, privacy, and operating review. Passage does not claim a completed certification, independent audit, or identity integration until it can be supported with evidence.
Bring your security questions.
We will show the current controls, evidence, open assurance work, and the boundary required before any approved pilot data is used.
Request a security review