Legal

Security

Last updated: July 2026

Our approach

Security is designed into every layer of our stack — from client-side validation to infrastructure hardening. This page summarises the controls we operate today.

Data protection

  • All traffic to our services is encrypted with TLS 1.2+.
  • Databases and object storage are encrypted at rest.
  • Row-level authorization guards applicant and client records.
  • Resume files are stored in a private bucket accessible only via short-lived signed URLs.

Access control

  • Least-privilege access; MFA required for all staff accounts.
  • Production changes go through peer review and audit-logged pipelines.
  • Secrets are rotated on a set cadence and after any personnel change.

Monitoring & response

We operate 24/7 SRE coverage with automated alerting for availability, latency and abuse signals. Security-relevant events feed a centralised, retained audit trail.

Responsible disclosure

If you believe you've found a security issue, please email security@ciagotech.com with a description and reproduction steps. We commit to acknowledge within 2 business days and to keep you informed through resolution. Please do not publicly disclose before we've had a chance to respond.