Developers
Security Overview
Last updated: August 2025
Introduction
Recruiting and HR data is critical to your business, and we take the security of customer data seriously. HireGrid is hosted on hardened infrastructure-as-a-service (IaaS) platforms from major cloud providers.
We do not claim SOC 2 certification at this time. We follow multi-tenant SaaS security practices and are transparent with teams that need signed reports or a security questionnaire before a pilot. Contact security@hirgrid.com for procurement review.
Product security
Authentication
HireGrid supports secure account authentication for workspace users. Where enabled for a customer, we support organization-controlled sign-in options appropriate to the deployment. Session credentials are protected in transit and expire according to product defaults and customer configuration.
Permissions
HireGrid supports role-based access for teammates. Permissions can be scoped to the organization and to hiring workflows so teams only see the jobs, candidates, and actions they need.
Physical security
HireGrid production data is processed and stored within data centers operated by our cloud providers, which commit to industry-leading physical security practices.
System security
Servers and networking
HireGrid application servers and structured datastores use managed infrastructure services provided and secured by our cloud providers.
Web traffic is encrypted in transit using HTTPS (TLS 1.2+) to protect requests against eavesdropping and man-in-the-middle attacks.
Storage
Persistent production data is encrypted at rest using industry-standard encryption provided by our cloud storage and database services.
Operational security
Policies
HireGrid maintains internal security policies covering access, data handling, and incident response. Policies are reviewed as the product and team scale.
Employee access
Access to production systems and customer data is limited to personnel who need it to operate or support the service. Administrative access is logged. Employee agreements include confidentiality obligations.
Code reviews and production deployment
Changes to source code go through review and automated checks before production deployment. Security-sensitive changes receive additional peer review covering security, performance, and potential for abuse.
Backups and recovery
HireGrid uses redundant datastores and backup practices aimed at limiting unintentional loss of customer data and supporting recovery from infrastructure failures.
Application security
Server and client hardening
Infrastructure is firewalled and rate-limited where appropriate. Request-handling paths use authorization checks and request verification. Client code uses standard browser protections against common web threats, including XSS and CSRF defenses, secure session handling, and session expiration.
API and integrations
Where APIs or integrations are available, access requires customer-controlled credentials or OAuth (or the mechanism required by the third-party app). Integrations are opt-in and can be disabled.
Customer payment information
Paid plans are billed through a PCI-compliant payment processor. HireGrid does not store full credit card numbers on our servers.
Incident reporting
Incident response
HireGrid follows a protocol for handling security events that includes escalation, mitigation, and post-incident review.
Responsible disclosure
HireGrid has a Responsible Vulnerability Disclosure program. You can read the rules of engagement and how to submit reports at hirgrid.com/vulnerability-disclosure.
If you have a security concern, question, or are aware of an incident, email security@hirgrid.com.