DocumentationAPI Reference
DocumentationAPI Reference

Security is at the core of our culture and we have operated from a security-first mentality from day one.

Persona's security philosophy follows three principles:

  • Building defense-in-depth against external threats
  • Protecting against human error
  • Guarding against misuse of insider access

For more information about our security measures, see our Security Statement or contact us.

Domains and IP Addresses

API access IP whitelisting

If you are calling our external API with static IP addresses and want an additional layer of security beyond API key based authorization, you can restrict the IPs that Persona accepts requests from. To whitelist IP addresses, visit the Development page within the Persona dashboard.

Webhook notifications

The full list of IP addresses that webhook notifications may come from is:

35.232.44.140
34.69.131.123
34.67.4.225

Embedded iframe

The Embedded Flow boots an iframe that loads Persona. If you'd like to restrict the allowed domains that are allowed to boot the Embedded Flow, you can configure allowed domains in the Development page within the Persona dashboard.