And make sure that the Jumio database is never hacked. Because once it's hacked you are ...cked.
As far as I know, Jumio shouldn't keep records, right? Jumio only verifies the identity (once!), then it's hash is stored in the DAG, and Jumio doesn't need your paperwork anymore. Jumio witnesses the hash is correct.
Im not sure if I am right here, but this would make perfect sense to me.
Cmon. Then how this KYC/AML works when needed? How three letter agency can find a user if they need by court order etc?