Security Architecture

Enterprise-grade infrastructure designed to protect your sensitive recruitment data. Last updated: July 2026.

AES-256 Encryption

All candidate data and uploaded resumes are encrypted at rest.

TLS 1.3 Transport

Every connection is secured with modern HTTPS protocols.

Secure Identity

Robust authentication managed exclusively by Clerk.

1. Security Overview

At Recruitarian, we understand that candidate data and hiring workflows represent some of the most sensitive information within your organization. We are committed to protecting your data through modern, cloud-native security practices, leveraging industry-leading infrastructure providers.

Our security program is designed around the principles of least privilege, defense in depth, and continuous monitoring to ensure your data remains secure, private, and available.

2. Infrastructure Security

Recruitarian is a modern, serverless application built on a highly secure technology stack. We do not maintain our own physical servers or data centers. Instead, we rely on top-tier infrastructure providers:

  • Netlify: Our application edge network and frontend deployment are managed by Netlify, providing DDoS protection, global edge caching, and secure content delivery.
  • Supabase: Our primary database (PostgreSQL) is hosted via Supabase, which implements strict physical and network security controls, continuous backups, and robust database-level isolation.

3. Authentication & Identity

We use Clerk, an enterprise-grade identity provider, to handle all user authentication and session management securely.

  • No Stored Passwords: Recruitarian LLC does not store or process your passwords directly. Clerk handles password hashing and secure token generation.
  • Secure Sessions: We utilize HttpOnly, secure cookies and short-lived session tokens to prevent unauthorized account access.
  • Identity Verification: Multi-factor authentication (MFA) and strict password policies can be enforced via the Clerk authentication layer to ensure only verified personnel access your workspace.

4. Data Encryption

We protect your data mathematically, ensuring it is unreadable to unauthorized parties whether it is moving across the internet or stored in our databases.

  • Data in Transit: All communication between your browser, our application servers, and our third-party APIs (Supabase, Clerk, OpenAI) is encrypted using modern TLS (Transport Layer Security) protocols. We enforce HTTPS across the entire platform.
  • Data at Rest: All customer data stored in our Supabase PostgreSQL databases is encrypted at rest using AES-256 encryption, an industry standard for data protection.

5. AI Security & Privacy

Recruitarian utilizes advanced Large Language Models (via OpenAI) to parse resumes, analyze candidate skills, and generate insights. We have implemented strict controls around how this data is handled.

  • No Foundational Model Training: The resumes, job descriptions, and recruiter notes you process through Recruitarian are sent to our AI providers via strict Enterprise API agreements. Your data is strictly excluded from being used to train or improve global foundational AI models.
  • Ephemeral Processing: AI analysis occurs synchronously, and the results are stored securely in your dedicated Supabase instance.

6. Access Controls & Data Protection

We limit internal access to customer data to ensure maximum privacy.

  • Internal Access: Only authorized engineering personnel have access to production databases, and such access is granted strictly on a "least privilege" basis required to maintain the platform or resolve support tickets.
  • Data Deletion: When you delete a candidate or a Hiring Board, the associated data is permanently and irrecoverably purged from our active databases.
  • File Storage: Uploaded resumes (PDFs, DOCX files) are stored securely and mapped directly to your authenticated session. Unauthorized users cannot arbitrarily access file URLs.

7. Customer Responsibilities

Security is a shared responsibility. While we secure the infrastructure and application, you play a critical role in keeping your recruitment data safe.

  • Protect Credentials: Use strong, unique passwords for your Recruitarian account and do not share login credentials across your team.
  • Control Access: Promptly remove user access when an employee leaves your organization.
  • Review Decisions: Always independently review AI-generated candidate summaries and Match Scores. You are responsible for your final hiring decisions and compliance with employment laws.

8. Responsible Disclosure

If you are a security researcher and believe you have found a security vulnerability in the Recruitarian platform, we encourage you to disclose it to us immediately.

Please email security@recruitarian.com with a detailed summary of the issue. We ask that you do not publicly disclose the vulnerability until we have had a reasonable timeframe to investigate and deploy a patch. We do not currently operate a paid bug bounty program, but we deeply appreciate responsible reports.

© 2026 Recruitarian LLC. All rights reserved.

Recruitarian