Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

An independent code review of Persona's data practices

We believe trust is earned through demonstration and transparency, not promises. That’s why we worked with Trail of Bits, an independent security firm that has spent years reviewing the code behind widely-used software from cryptography libraries to critical open-source infrastructure. Persona regularly undergoes independent third-party audits across our security, privacy, and product programs.

7 Best Endpoint Security Software for Businesses

Picking the best endpoint security for business depends on your org's size, stack, and how much in-house security muscle you actually have. CrowdStrike Falcon leads on pure detection, Microsoft Defender wins on value for M365-heavy shops, miniOrange is the strongest choice for mid-market businesses that need identity-first device security without the enterprise price tag, and IBM MaaS360 covers the UEM-first crowd that needs mobile + BYOD sorted from a single console.

mTLS for AI Agents

AI agents are increasingly accessing APIs, databases, SaaS applications, MCP servers, and other services without human intervention. As these autonomous systems become part of enterprise infrastructure, organizations need reliable ways to verify their identity before granting access to sensitive resources. Traditional authentication methods such as API keys and bearer tokens were designed for applications and users, not autonomous agents operating continuously across distributed environments.

GenAI fraud detection in academia vs industry

Academic fraud datasets often lack real-world grounding and miss insights that you can only glean from defending against ongoing adversarial attacks. Just ask Zhaofeng Si, a PhD student in computer science at the University at Buffalo who studies the detection of AI-generated synthetic images. Three weeks ago, he joined Persona for a 12-week internship. Now, he’s working alongside Persona’s research scientists to build a benchmark for selfie fraud.

Persona supports France and Germany EUDI Wallets for secure, private identity verification

Across Europe, two major regulatory deadlines are arriving that will reshape the mechanics of identity verification for EU-regulated businesses. By the end of 2026, eIDAS 2.0 will require organizations to accept EUDI Wallets for online services where electronic identification or authentication is necessary. That obligation covers state, regional, and local authorities; bodies governed by public law; and certain private entities that are required to provide public services.

RBAC vs. ABAC: Core Differences, Use Cases, & The AI Agent Era

As organizations expand across cloud platforms, SaaS applications, remote teams, and AI-driven systems, managing access becomes more challenging. Security teams must ensure users, applications, and automated workflows can access the resources they need without exposing sensitive data or critical systems. This is where the RBAC vs ABAC discussion becomes important.

Turn Jira Service Management into a Governed Access Control Platform

As a fintech organization, you depend on multiple systems like AWS, Databricks, Snowflake, Power BI, Stripe Treasury, Identity Providers (IdP), developer tools, internal operational platforms, and many more. Managing access and access level across platforms is often disconnected and spread across emails, Slack approvals, tickets, and sometimes spreadsheets. Obviously, this is inefficient. There'll be delays in onboarding. But that's the least of your worries.

ANPD's age assurance mechanisms guidance: What Brazil's new risk framework means for compliance

On May 22, Brazil’s National Data Protection Agency (ANPD or Agência Nacional de Proteção de Dados) published new draft guidance on age assurance (aferição de idade) mechanisms. The guidance provides companies with their clearest picture yet of how to comply under the Digital ECA. Part of a broader rollout of Brazil’s Digital ECA framework, the guide emphasizes risk-based proportionality and privacy by design (privacidade desde a concepção).

Agentic IAM: The Complete Guide to Identity Security for Autonomous AI Agents

If you’ve deployed your first AI agent, then you must have given it access to your CRMs, ticketing systems, and your cloud storage. This AI agent is programmed to run 24/7, make decisions, call external APIs, and trigger actions (without a human in the loop). Now, answer these questions: If you cannot answer these questions, then you have an agentic AI identity issue. Traditional Identity and Access Management (IAM) was built for service accounts with static API keys and users with usernames.

Clean Up Jira and Confluence Attachments Before Atlassian Cloud Migration

Since the announcement of the Atlassian Data Center end-of-life, organizations have started planning their migration to the cloud. However, it’s not a simple copy-and-paste job. Over time, your Jira and Confluence instances accumulate years of attachments. These might include screenshots, log files, ZIP files, duplicate uploads, and other items nobody remembers uploading. You might not even realize these files exist until migration begins and the bloat starts causing delays.