Legal
Security
Last updated: July 2026
Our approach
Security is designed into every layer of our stack — from client-side validation to infrastructure hardening. This page summarises the controls we operate today.
Data protection
- All traffic to our services is encrypted with TLS 1.2+.
- Databases and object storage are encrypted at rest.
- Row-level authorization guards applicant and client records.
- Resume files are stored in a private bucket accessible only via short-lived signed URLs.
Access control
- Least-privilege access; MFA required for all staff accounts.
- Production changes go through peer review and audit-logged pipelines.
- Secrets are rotated on a set cadence and after any personnel change.
Monitoring & response
We operate 24/7 SRE coverage with automated alerting for availability, latency and abuse signals. Security-relevant events feed a centralised, retained audit trail.
Responsible disclosure
If you believe you've found a security issue, please email security@ciagotech.com with a description and reproduction steps. We commit to acknowledge within 2 business days and to keep you informed through resolution. Please do not publicly disclose before we've had a chance to respond.