Information security
and data privacy

Information security
and data privacy

Trust, by design

Every product we build and every process we run is engineered to keep customer data secure, compliant, and private. Not as policy, but as architecture.

  • Independently certified: ISO 27001:2022
  • EU compliant: GDPR
  • India compliant: DPDP Act
  • Multi-region: Hosted on AWS

Trusted by enterprises across industries


Our principle: Many layers. One foundation.

Security at HirePro means upholding confidentiality, integrity, availability, and accountability in parallel, never trading one against another. The engineering convictions that follow run through every layer of the platform.

Architecture, not policy

Protection lives in the system itself. Policy is enforced by procedure; architecture is enforced by the system, where it cannot lapse, be overridden, or quietly drift.

Depth, not perimeter

No single control carries the weight. Encryption, access control, segregation, logging, and testing operate as independent layers; the compromise of one does not compromise the others.

Evidence, not assertion

Anyone can claim to be secure. We hold ourselves to certifications, third-party pen tests, and customer-accessible audit logs. All of it is available for independent review.

“Security and compliance are not features we add. They are the foundation everything else is built on.”


Certifications: Independently certified. Regularly audited.

Compliance is not a one-time exercise. Our certifications are validated by external bodies and re-validated through periodic surveillance audits. The frameworks underneath give your legal, privacy, and procurement teams a known baseline to evaluate us against.

01. International standard: ISO/IEC 27001:2022

Certified to the global standard for information security management. An independent body has validated that our controls, covering access, encryption, incident response, and more, meet ISO requirements, and we maintain certification through ongoing surveillance audits.

02. European Union: GDPR compliant

Aligned with the EU General Data Protection Regulation. We honour the lawful basis, purpose limitation, data subject rights, and breach notification obligations GDPR requires, regardless of where your organization operates.

03. India: DPDP Act compliant

Aligned with India’s Digital Personal Data Protection Act, 2023. We honour consent, purpose limitation, and data principal rights, and our regional data residency options support compliance with local processing requirements.


Testing protocol: We attack ourselves before anyone else can

Our systems are tested continuously and exhaustively. Automated scanners run around the clock; a security team reviews what automation misses; and an independent security firm regularly attempts to compromise our systems the way a real attacker would.

Penetration testing: Regular third-party offensive testing

At a defined cadence, an independent security firm attempts to compromise our systems using the same techniques a real attacker would. Findings, scored by CVSS severity, feed directly into our remediation backlog. High-severity issues are prioritized first, every time. Executive summaries are available to customers on request.

  • Independent firm: External offensive team, fresh perspective
  • CVSS scoring: Objective severity, prioritized remediation
  • Reports on request: Available under NDA to qualified buyers

Vulnerability scanning: Continuous automated and manual review

Automated scanning covers our infrastructure, container images, dependencies, and application stack, surfacing known vulnerabilities as they emerge upstream. Manual security reviews catch the issues automation misses. Both feed a single prioritized backlog tracked against defined remediation SLAs.

  • Always-on automation: Infrastructure, code, dependencies
  • Manual reviews: Human judgement where it counts
  • Defined SLAs: Critical and high issues resolved on a clock

Infrastructure: Built on the most-trusted cloud

HirePro runs on Amazon Web Services, one of the world’s most secure and audited cloud platforms. AWS’s own compliance attestations sit underneath ours, giving you defense-in-depth from the silicon up.

Hosted on AWS

Production workloads run on Amazon Web Services, and are certified to SOC 1/2/3, ISO 27001, FedRAMP, and dozens of other frameworks. We inherit those controls; you benefit from them. Each AWS region we operate in runs inside its own Virtual Private Cloud, isolated at the network layer from the public internet.

Dedicated VPC

Customer workloads are segregated at the application and database layer, with tenant context enforced at every query, every API call, and every background job. A misconfigured permission in one place cannot bypass enforcement in the others; segregation is defended in depth, not at a single boundary.

Regional data residency

Choose where your data lives. We host in three AWS regions: India, Singapore, and Ireland, supporting the residency requirements of customers operating under frameworks that restrict cross-border data transfers.


Data protection: Encrypted everywhere. End-to-end.

Encryption is table stakes, but the details matter. We protect data in motion and at rest using the same algorithms trusted by governments and financial institutions, with keys managed and rotated to limit exposure even in worst-case scenarios.

Data in transit: TLS 1.2 and 1.3 with strong ciphers

All data moving between your systems and HirePro is encrypted using Transport Layer Security with modern cipher suites. We enforce HSTS to prevent protocol downgrade attacks, and certificate lifecycle is automated. Data flowing between our own services is encrypted with the same rigour.

  • TLS 1.2/1.3: Modern ciphers only. Legacy protocols disabled.
  • HSTS enforced: Prevents protocol downgrade
  • Automated certificates: Rotation managed; no surprise expiries

Data at rest: AES-256 with managed keys

All stored data is encrypted using AES-256, the algorithm used by governments and banks globally. Encryption keys are managed through AWS Key Management Service (KMS) and rotated on a regular schedule, limiting exposure in the unlikely event a key is ever compromised.

  • AES-256: Industry-standard at-rest encryption
  • AWS KMS: Centralized key management and audit trail
  • Regular key rotation: Limits the window of any potential exposure

Access control: Granted on need. Never broader.

Every user, every system component, every internal service operates under least privilege. Access is granted by role and authenticated to match your enterprise model, federated through single sign-on, or enforced at the platform layer with multi-factor authentication.

  • RBAC (Role-based access): Permissions assigned by role, not by user. People see only what their role requires.
  • SSO (Single sign-on): SAML 2.0 federation with your existing IdP. One set of credentials, centrally managed by you.
  • MFA (Multi-factor auth): Optional multi-factor authentication for customers not using SSO. Stops credential theft cold.
  • Least privilege (Minimum by default): Every account, every service, every integration: only the access strictly required.

Visibility: Logged. Auditable. Verifiable.

Trust requires evidence. Every significant action in the platform is logged with full context: who acted, on what, when, and from where, and our systems monitor the stream for anomalies in real time. Your team has direct access to the data and logs you need day-to-day; deeper audit records come from our security team on request.

01. Complete audit trails

Authentication, configuration changes, data access, administrative actions, every significant event captured, immutable, and time-stamped. Retention is aligned to regulation.

02. Direct customer access

What you need for day-to-day operations, candidate activity, and configuration changes is directly accessible to your team. Deeper records come from our security team on request.

03. Real-time anomaly detection

Our systems continuously analyze login patterns, access geographies, and behavioral signals. Unusual events trigger alerts before they escalate into incidents.


Secure development: Security built in. Not bolted on.

The most reliable place to stop a vulnerability is before it is written. Our development lifecycle bakes security in at the design stage, with reviews and threat modelling before any code ships.

SDLC: OWASP-aligned development

Our developers build against the OWASP Top 10, the industry-recognized list of the most critical web application security risks. Addressing those at the code level means fewer vulnerabilities ever reach production.

  • Code reviews on every change, security-aware
  • SAST + DAST in CI for static and dynamic analysis
  • Dependency scanning with auto-remediation where safe

Threat modelling: Designed against attack

Every significant new feature goes through structured threat modelling before code is written. We identify how it could be attacked, decide how to defend against it, and design those controls in from day one.

  • STRIDE-based modelling on new features
  • Risks tracked alongside engineering work
  • Architecture review for any change touching trust boundaries

Resilience: Available when it matters most

Hiring does not pause for outages. Our infrastructure is distributed, backed up, and tested against the scenarios most organizations never plan for.

Geo-redundancy

Infrastructure distributed across multiple AWS regions with automatic failover. If one region experiences a disruption, traffic shifts without manual intervention. Your team stays online; your candidates keep moving through the funnel.

Regular backups

Point-in-time backups are taken at regular intervals across critical data stores. Restore procedures are tested on a schedule, not assumed to work. Recovery objectives are documented, not aspirational.

Business continuity

A documented BCP covers people, infrastructure, and operations through any significant disruption, from regional outages to scenarios most organizations never consider.


Trust, layer by layer.

Secure by design. Verified independently.