Trust & Security
How IONDRA protects customer data, governs the open MCA specification, and publishes verifiable proof of its own attestation log integrity.
Data protection
We collect only what fraud detection and account operation require, encrypt it at rest and in transit, and isolate every organization's data from every other's. Access is governed by role-based permissions and multi-factor authentication, and changes to sensitive records are captured in a tamper-evident audit log.
Full details, including your rights over your data, are in our Privacy Policy and Terms of Service.
Responsible disclosure
Found a security issue? Report it through our published disclosure contact at /.well-known/security.txt (RFC 9116), or reach us directly via Contact.
MCA governance
The MCA specification is developed in the open on GitHub under a documented governance process, with a public changelog for every revision.
The specification and its reference verifier are published and maintained by the spec's editor, Ijeoma Silver Nsaka, under his personal GitHub account — IONDRA does not yet operate a separate GitHub organization for MCA.
Log integrity & conformance
IONDRA's codebase currently passes 9/9 repository checks against vendored mca-verify reference vectors. This is a reproducible fixture result, not a claim that the public log currently contains a checkpoint or is healthy.
The public descriptor advertises the reference-log endpoints; its availability alone is not a health signal. Check the latest-checkpoint response before making an integrity claim. A missing checkpoint or empty Merkle root means there are no checkpointed records to verify and must not be presented as a healthy live log. The open-source verifier can be run without a paid service.
See the full MCA overview and FAQ for more.