Trust & Compliance

We weigh hashes — never your users' raw device.

Device reputation shouldn't mean surveillance. HWID-Guard is built so that the sensitive data stays on the client, and only what's needed to make a verdict ever reaches us — hashed.

Last updated: August 2026 · Pre-launch — see the honest status below.

The one thing to know: your client hashes the device identifiers before they leave the machine. HWID-Guard receives and stores only the hash — the raw serial, MAC, or hardware ID never reaches our server. Reputation is computed over hashes.

01 · Data minimization

What we store — and what we never touch

02 · Regulations

LGPD & GDPR posture

Hashing at the source is a privacy-by-design choice — it's what lets HWID-Guard do device reputation without holding a raw, re-identifiable hardware fingerprint. Roles are clear:

03 · Security

How it's protected

ControlWhat it means
Hashes onlyRaw identifiers never reach or persist on the server.
Secrets encrypted at restWebhook/integration secrets are encrypted in the database (configurable key / KMS).
Scoped API keysKeys carry least-privilege scopes; IP allowlists and self-service revocation available.
Audit logBans, key actions, and security events are recorded and exportable.
No error leakageValidation errors don't echo submitted values back — a secret sent by mistake won't surface in a response.
04 · Honesty

What HWID-Guard is not

We'd rather tell you the limits up front

Not antivirus, not a kernel anti-cheat. Reference collection is user-mode (SDK/agent) — we don't ship a tamper-proof driver or promise to stop a kernel-level attacker.

Detection is heuristic. It's weighted evidence, not proof of identity. A determined attacker with a capture card, a spoofer, or hardware swaps can work around signals — we design for cost, not certainty.

Not legal proof of device ownership. A device binding is a reputation signal, not a court-grade attribution.

This honesty is deliberate. If a page tells you a security product is infallible, it's lying to you.

05 · Status

Certifications & roadmap — where we actually are

HWID-Guard is pre-launch. We won't claim certifications we don't hold. Here's the real picture:

LivePrivacy-by-design architecture (hashes only, data minimization)
LiveEncryption at rest for secrets, scoped keys, audit log
RoadmapConfigurable per-tenant data retention & deletion controls
RoadmapFormal SOC 2 / independent security audit
RoadmapSigned DPA & sub-processor list for enterprise

Doing a security review?

Send your questionnaire — we answer plainly, and we'll tell you where we're not there yet rather than paper over it.

Contact us