How We Protect Anonymity

How We Protect Anonymity

We’ve seen questions from the community about how Blind protects anonymity and how re-verification works. We want to walk through exactly how the system works and reaffirm our promise to you.

Blind is built so identities cannot be reconstructed

Blind was designed to prevent activity on the platform from being traced back to a verified identity.

The system and method behind Blind’s authentication is patented.

At a high level, the system verifies that someone belongs to a company while separating the company email used for verification from the information used to access and use the service. The email used for verification is encrypted into a non-public value and securely stored, and that no one (including Teamblind employees) can decrypt it back to the original email.

This separation ensures that activity on Blind cannot be traced back to the identity information used during verification.

If you’re curious about the technical details, feel free to read the full patent specification.

Verification confirms employment, not identity

When someone signs up, Blind verifies that the user belongs to a company through their company email address.

​​The encrypted email and the account required to use the service are stored in completely separate databases, and they contain no identifiers or clues that could be used to match them. 

Because of this, functions that are common in other services (such as password recovery or requests to view a user’s activity history) are not possible in Blind.

In short, Blind verifies company membership, but the system architecture prevents that verification data from being connected to posts or activity.

How re-verification works when someone leaves a company

Blind has the ability to re-verify employment when someone leaves a company to maintain a community for current employees. This can happen in two ways:

  1. Our community team may initiate a re-verification process based on a user’s activity (such as a post or comment suggesting they may no longer work at the company).
  2. Blind may receive company email addresses from companies registered on Blind solely to identify users who should no longer have access to a company channel.

When this happens, the email address is processed into the same one-way hashed form used by our verification system and compared against verification records.

If there is a match, Blind can:

• terminate the connection between the device and the server• remove access to company-specific channels

This process works without identifying the specific user behind the account.

Why authors remain anonymous

Blind has operated with this architecture for more than 12 years. During that time, there has not been a single instance where an author’s identity was revealed by Blind.

This is because the system is designed so that the identity information used during verification and the activity on the platform exist in separate domains that cannot be joined.

Blind’s ability to verify company communities while protecting individual anonymity is foundational to the product and to the trust our community places in us.