Explore how identity, organizational records and module-specific information are treated across HireFlow360, ProfileX and VeraClare. Ask our team for the current security documentation and deployment-specific controls.
These workflows describe the intended platform scope. Confirm the available controls, configuration and supporting evidence for your deployment before relying on them. A listed framework or security practice is not a claim of completed certification.
A ProfileX identity connects services; it does not merge their records. The professional profile, company employment record and VeraClare background record each keep their own purpose and permissions.
Protect information in transit and at rest, including backups and sensitive documents. Review the actual algorithms, key ownership and rotation arrangements for the services in your deployment.
Connect company identity and employment changes to account access. The enterprise design covers SAML 2.0 and OpenID Connect sign-in, with SCIM provisioning and deprovisioning.
The authentication design includes stronger factors and organization-specific enforcement. Confirm the supported factors for your identity provider and the account recovery process.
Give recruiters, managers, HR and administrators the minimum access their responsibilities need. Separate access to a role or employment record from access to sensitive personal evidence.
The intended sharing workflow automatically expires employment-linked consent at offboarding. The person can also revoke a grant earlier; the organization retains only the records it is entitled to keep under its separate retention rules.
Record who accessed information, what action was taken, the relevant organization and purpose, and when it happened. Connect human decisions, API calls and system events so an investigation can follow the whole workflow.
Infrastructure review covers isolation, traffic protection and deployment boundaries. Controls vary by hosting service and plan; the review should identify what is enabled and who operates it.
Recovery planning covers automated backups, point-in-time restoration and the loss or failure of a service. Agree recovery objectives against the actual backup configuration and the results of restoration exercises.
Security review belongs in the release process. The development program covers code review, static analysis, dependency and container scanning, with a route to investigate and resolve findings.
Staff access needs the same clear ownership as product access. The security program includes role-appropriate training, authorized background checks and timely removal of access when duties change.
Prepare for detection, containment, investigation and recovery, with named owners and an escalation route. Notification obligations and timing follow the applicable agreement and incident circumstances.
Request the current security questionnaire, control inventory, testing scope and remediation status. For SOC 2 or ISO 27001 requirements, review the actual report or certificate, covered services and audit period. For healthcare or government use, confirm applicable agreements and authorization requirements before providing sensitive information.
HIPAA/BAA or FedRAMP requirements are assessed for the proposed service; their mention here does not assert readiness or authorization. Availability, recovery and notification commitments are those agreed in the contract.
Explore governance workflows →