Trust & Security

Trust Center

Plain English, no marketing gloss. Everything below is either implemented today or on the roadmap with a target quarter. Version 2026-02-15.

Encryption

In transit: TLS 1.2+ on every endpoint. HSTS enabled.
At rest: AES-256 on database volumes and object storage.
Sensitive PII fields: Fernet-encrypted before insert (identity numbers, DOBs, screening artifacts).
Passwords: Bcrypt hashed. Plaintext passwords never touch the database or logs.

Access controls

PII in admin views is masked by default — reveal requires an explicit click.
Every reveal writes an audit log entry (who · when · which field · which subject).
Role-based auth (professional · employer · admin · support-admin · platform-admin) — no role can act outside its scope.
Session tokens rotated on password change or role escalation.
Production infrastructure access limited to on-call engineers. No standing shell access.

AI data handling

Only the fields required for the specific AI feature are sent — no bulk resume dumping.
OpenAI + Gemini are called in zero-retention / no-training API modes. Your data is not used to train third-party models.
Generated outputs (hiring briefs, resume drafts, mock-interview scores) are written to your Simonara account only.
Every AI feature is opt-in and can be turned off per workspace.

Retention & deletion

Personal data is deleted within 30 days of account closure — including resumes, chat threads, and passport artifacts.
Audit logs retained for 12 months for security-incident forensics, then rotated out.
Background verification records governed by FCRA (7 years) via Checkr — Simonara does not host the raw report.
Backups rotate on their normal schedule (max 90 days) after account deletion.

Subprocessors

Simonara publishes every subprocessor that processes customer data — what they do, what data flows to them, where they operate, and how long they hold it.

See the full subprocessor list

Customers on a signed DPA get 30-day notice before any subprocessor change.

Roadmap to SOC 2

Now: Encryption, access controls, audit logging, DPA + subprocessor register live.
Q2 2026: Formal information-security policy set + vendor risk-review process.
Q3 2026: Kick off SOC 2 Type I readiness assessment with a qualified auditor.
Q4 2026 / Q1 2027: Target SOC 2 Type II observation window.

We won't claim certifications we don't hold. Progress updates land here as milestones close.

Security questions? Email security@simonaratalent.us — a real human answers within one business day.

AI-powered talent platform

Ready to Experience Smarter Hiring?

Whether you're looking for your next opportunity or your next great hire, Simonara AI helps you move faster with verified Talent Passports and intelligent matching.