Skip to main content
Candidately Trust Center

Candidately Trust Center

Welcome to Candidately's Customer Trust Portal. Our commitment to data privacy and security is embedded in every part of our business. Use this portal to learn about our security posture and request access to our security documentation.

security@candidate.ly

Documentation

Subprocessors

Amazon Web Services
Amazon Web Services · USA
Cloud infrastructure hosting
Google Cloud
Google Cloud · USA
Cloud infrastructure hosting
Weaviate
Weaviate · EU
Vector database
Cloudflare
Cloudflare · USA
Network security and CDN
OpenAI
OpenAI · USA
AI model provider

Controls

Access control

Controls governing who can access systems, data, and infrastructure, and under what conditions.

Role-based access control
Least privilege enforcement
Multi-factor authentication
Privileged access management
Separation of duties
Automated access provisioning and deprovisioning
Quarterly access reviews
Password policy and manager
Data security

Controls protecting the confidentiality, integrity, and availability of data across all states and systems.

Encryption at rest
Encryption in transit
Application-level encryption for sensitive data
Data classification framework
Data retention and deletion policy
Secrets management
Multi-tenant data isolation
Application security

Controls embedded in the software development lifecycle to prevent vulnerabilities from reaching production.

Secure software development lifecycle
Mandatory code review with two approvals
Automated CI/CD security scanning
Dependency vulnerability management
Annual penetration testing
Responsible disclosure program
Web application firewall