Security Center
How data is protected on Expertini ATS, and how to report a security issue responsibly.
This page covers the security practices relevant to a recruiter or hiring organisation evaluating the platform, and the responsible-disclosure process for reporting a vulnerability.
On this page
01Infrastructure
Expertini ATS runs on infrastructure operated directly by Expertini (not a resold third-party SaaS), on a dedicated Elasticsearch cluster with TLS in transit. Payment data is handled entirely by Stripe — card details never touch Expertini's own servers.
02Access control
Organisation data is strictly scoped by org_id at the data layer — one hiring organisation cannot query or view another's candidates, jobs, or applications. Within an organisation, owner/admin/recruiter roles control who can do what (e.g. only owners/admins can delete a client record in Client CRM).
03PII handling
Personal identifiers are pattern-stripped from CV text before any AI scoring step reads it — see the Privacy Policy for the full detail on what's stripped and the limits of that process.
04Responsible disclosure
Found a security vulnerability? Email security@expertini.com with reproduction steps. Please report privately before any public disclosure, and avoid accessing or modifying data beyond what's needed to demonstrate the issue — we don't currently run a paid bug-bounty program but do acknowledge good-faith reports.
05Data retention and deletion, concretely
Candidate application data is deleted automatically after 24 months — a scheduled process, not a request-only right the candidate has to know to exercise. Organisation secrets configured for integrations are stored server-side and never re-rendered back to a browser: once saved, the interface shows only that a credential exists, not its value. Payment card data never exists on Expertini systems at any point — the entire card lifecycle happens inside Stripe. The Privacy Policy is the authoritative statement of retention periods and data-subject rights; this page's job is the security-relevant summary.
06Answers to the questions security reviewers actually ask
For teams running a vendor security assessment, the short versions: tenant isolation is enforced at the data layer on every query (org-scoped filtering, not application-code convention alone). Role-based access separates owner/admin actions (billing, seats, deletion) from day-to-day recruiter work. Candidate PII is pattern-stripped before CV text reaches any AI processing step — the AI evaluates evidence, not identity, as detailed on the AI technology page. Transport is TLS; infrastructure is operated directly by Expertini rather than resold. And the scoring pipeline's decisions are reproducible and logged with dimension-level rationale — relevant to security reviews that now include algorithmic-accountability questions. For anything this summary doesn't cover, security@expertini.com answers assessment questionnaires directly.
Frequently asked questions
Is there a paid bug bounty?⌄
Can Expertini staff see our candidate data?⌄
Who fills in our vendor security questionnaire?⌄
At a glance
- Org data strictly scoped by org_id — no cross-organisation visibility
- Card details handled entirely by Stripe, never stored by Expertini
- PII pattern-stripped before any AI scoring step
- Responsible disclosure via security@expertini.com, report privately first
- 24-month automatic candidate-data deletion, scheduled not request-only
- Integration secrets never re-rendered to the browser after saving
See security center on your own hiring.
Bring a real job description to a 30-minute demo — free trial included.
Book a demo