Legal document

Security summary

Controls actually documented in the stack.

Version:
2026.07.25
Effective:
July 25, 2026
Updated:
July 25, 2026

1. Documented controls

  • TLS in transit on production HTTPS deployments.
  • Per-app access controls (JWT/session auth, internal admin roles where present).
  • Secrets via environment variables / infrastructure secret stores.
  • Sensitive field encryption in Recruit (transcripts) when FIELD_ENCRYPTION_KEY is configured.
  • Logical multi-tenant isolation at application data level.

We do not claim SOC 2, ISO 27001, or other certifications. We do not claim 24/7 monitoring or specific RPO/RTO backups without published operational evidence.

This document is informational and contractual as applicable. It is not legal advice.