Security
Last updated: June 1, 2026
Infrastructure Security
We deploy and operate on an isolated tenancy infrastructure, featuring hardened Linux hosts, automated patching mechanisms, and weekly vulnerability scans. All production deployments undergo rigorous code review, automated testing, and a carefully managed staged rollout process to ensure stability and security.
Data Encryption
All data, both at rest and in transit, is protected with industry-leading encryption standards. Data at rest is encrypted with AES-256, and data in transit is secured using TLS 1.3. Furthermore, CV files are stored in object storage utilizing per-tenant encryption keys managed through a Key Management System (KMS).
Access Control and Management
Access for our engineering team to production data is strictly restricted to on-call staff only, requires multi-factor authentication (MFA) with hardware tokens, and all access is comprehensively logged for audit purposes. We adhere to the principle of least privilege and ensure credentials are rotated every 90 days.
Compliance and Certifications
We are actively pursuing SOC 2 Type II certification and are fully aligned with GDPR and POPIA regulations. A Data Processing Addendum is available upon request for our Scale plan customers.
Backup and Disaster Recovery
Our data is backed up through hourly snapshots with a 30-day retention period. We have a well-documented disaster recovery plan that is tested quarterly, targeting a Recovery Point Objective (RPO) of 4 hours and a Recovery Time Objective (RTO) of 24 hours.
Responsible Vulnerability Disclosure
If you discover a potential security vulnerability, we urge you to report it responsibly by emailing security@talentkasi.io. We commit to acknowledging all reports within 24 hours and operate a coordinated disclosure program, offering rewards for valid and impactful reports.