Skip to content
CandidateBrief
Menu
Sign in
Start free trial
Security

Security and data handling

What this product does with a candidate’s document, stated as mechanisms rather than adjectives. Each of these is something you can ask us to demonstrate.

Mechanisms

How the data is protected

One agency cannot see another

Every table carries the agency it belongs to, and the database enforces it. A query that forgets its scope returns nothing rather than another agency’s candidates, and that is tested from both sides.

Files live in a private bucket, with no public links

Downloads go through an authorised route that records the access, rather than a signed link that works for anyone who can see the address bar. Storage keys are built from ids and hashes, so a key never contains a name.

A retention window you choose

Seven, thirty or ninety days, or deletion on request. When the window closes, the uploaded original and the generated files are removed; the confirmed fields and the review history stay, so a profile still reads correctly.

De-identification regenerates, it does not mask

The de-identified pack is produced from filtered data, so filenames, document properties, headers, footers and link targets are in scope too. There is no code path that renders the full document and then hides parts of it.

Permissions are enforced by the server

Five roles, checked on every request from stored membership rather than from a session cookie. Removing someone takes effect on their next request, whatever their browser still has open.

Changes are recorded

Approvals, exports, share links, deletions and permission changes are written to an append-only log with who, what and when — and the usage ledger records every unit held and settled, so an invoice can be explained line by line.

What we are not claiming

The list of third parties involved is on the Sub-processors

  • No security certification. We have not been audited against ISO 27001, SOC 2 or anything comparable, and we will not imply otherwise.

  • No independent penetration test has been commissioned. The cross-tenant, replay and file-attack suites exist, but a suite we wrote is not a third-party assessment.

  • Deletion is not instant everywhere. Files and database rows go immediately; encrypted backups expire on their own schedule, and the date is shown on the deletion record.

  • This deployment is a pilot: the operating entity, the payment account and the email provider are not settled yet, so the sub-processor list below is provisional.

Ask us to demonstrate any of it

Write to one address with a question about any mechanism above, or with a data request.

Security and data handling · CandidateBrief