Security Center
SUPPORT · EXPERTINI ATS

Security Center

How data is protected on Expertini ATS, and how to report a security issue responsibly.

2 min read · Updated July 2026 · Expertini Editorial

This page covers the security practices relevant to a recruiter or hiring organisation evaluating the platform, and the responsible-disclosure process for reporting a vulnerability.

01Infrastructure

Expertini ATS runs on infrastructure operated directly by Expertini (not a resold third-party SaaS), on a dedicated Elasticsearch cluster with TLS in transit. Payment data is handled entirely by Stripe — card details never touch Expertini's own servers.

02Access control

Organisation data is strictly scoped by org_id at the data layer — one hiring organisation cannot query or view another's candidates, jobs, or applications. Within an organisation, owner/admin/recruiter roles control who can do what (e.g. only owners/admins can delete a client record in Client CRM).

03PII handling

Personal identifiers are pattern-stripped from CV text before any AI scoring step reads it — see the Privacy Policy for the full detail on what's stripped and the limits of that process.

04Responsible disclosure

Found a security vulnerability? Email security@expertini.com with reproduction steps. Please report privately before any public disclosure, and avoid accessing or modifying data beyond what's needed to demonstrate the issue — we don't currently run a paid bug-bounty program but do acknowledge good-faith reports.

05Data retention and deletion, concretely

Candidate application data is deleted automatically after 24 months — a scheduled process, not a request-only right the candidate has to know to exercise. Organisation secrets configured for integrations are stored server-side and never re-rendered back to a browser: once saved, the interface shows only that a credential exists, not its value. Payment card data never exists on Expertini systems at any point — the entire card lifecycle happens inside Stripe. The Privacy Policy is the authoritative statement of retention periods and data-subject rights; this page's job is the security-relevant summary.

06Answers to the questions security reviewers actually ask

For teams running a vendor security assessment, the short versions: tenant isolation is enforced at the data layer on every query (org-scoped filtering, not application-code convention alone). Role-based access separates owner/admin actions (billing, seats, deletion) from day-to-day recruiter work. Candidate PII is pattern-stripped before CV text reaches any AI processing step — the AI evaluates evidence, not identity, as detailed on the AI technology page. Transport is TLS; infrastructure is operated directly by Expertini rather than resold. And the scoring pipeline's decisions are reproducible and logged with dimension-level rationale — relevant to security reviews that now include algorithmic-accountability questions. For anything this summary doesn't cover, security@expertini.com answers assessment questionnaires directly.

Frequently asked questions

Is there a paid bug bounty?
Not currently — stated plainly rather than implied otherwise. Good-faith reports are acknowledged and acted on, and private-first disclosure is the one firm ask.
Can Expertini staff see our candidate data?
Operational access is limited to what running and supporting the service requires — there's no cross-tenant browsing interface, and org-scoped filtering applies at the data layer, not just in the UI.
Who fills in our vendor security questionnaire?
Send it to security@expertini.com. The sections above cover the most common questions (isolation, retention, payment handling, AI data flow) if you need answers before a formal review.

At a glance

  • Org data strictly scoped by org_id — no cross-organisation visibility
  • Card details handled entirely by Stripe, never stored by Expertini
  • PII pattern-stripped before any AI scoring step
  • Responsible disclosure via security@expertini.com, report privately first
  • 24-month automatic candidate-data deletion, scheduled not request-only
  • Integration secrets never re-rendered to the browser after saving

See security center on your own hiring.

Bring a real job description to a 30-minute demo — free trial included.

Book a demo
Expertini AI
Online now
Hi! I'm Expertini's AI Product Expert. Ask me anything about our solutions, get guidance on any of our Hiring Tools, or just tell me what you're trying to do — I'll point you in the right direction. For account-specific issues, email support@expertini.com.