Security
How we protect your data
Candidate and HR data is sensitive. Here is exactly how we protect it.
Encrypted in transit
All data between your browser and our servers is encrypted using HTTPS/TLS 1.3. No data is ever transmitted in plain text.
Encrypted at rest
Data at rest is encrypted using AES-256 via Supabase (PostgreSQL). Database credentials are rotated regularly and never committed to source code.
Hosted in India
All data is stored on AWS ap-south-1 (Mumbai, India) via Supabase. No data leaves Indian jurisdiction without explicit consent.
Daily automated backups
Supabase takes daily automated backups retained for 7 days. Point-in-time recovery is available on Pro tier.
Auth via sign in link
HR users authenticate via Supabase sign in link - no passwords stored. Session tokens are scoped and short-lived.
Sandboxed code execution
Candidate code runs in a Judge0 sandbox on an isolated Hetzner VPS. Execution is time- and memory-limited. The sandbox has no internet access.
Data retention limits
Candidate data is deleted 90 days after assessment completion. Organisation data is deleted 90 days after account cancellation.
No third-party data selling
Candidate or HR data is never sold to, shared with, or monetised by third parties. AI features use only anonymised aggregate statistics - no individual records.
Found a vulnerability?
Please report it responsibly to us via our contact form. We will respond within 48 hours.