Security, Privacy & Compliance
How NoticeScale safeguards your organization's candidate data, employment records, and recruitment workflows.
AES-256 & TLS 1.3 Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 standard encryption. Sensitive candidate files (KTP, NPWP, offers) are stored in isolated encrypted S3 vaults.
Multi-Tenant Isolation & RLS
Complete tenant data isolation enforced via PostgreSQL Row Level Security (RLS). Organization data is strictly separated to guarantee zero cross-tenant leakage.
Granular Role-Based Access (RBAC)
Fine-grained permissions for Client Owner, HR, Recruiter, and Interviewer roles. Hide salary expectations, identity documents, and sensitive notes from unapproved team members.
GDPR & Candidate Consent
Built-in GDPR compliance tools including candidate data deletion requests (Right to be Forgotten), automated data retention policies, and full audit logging.
1. Infrastructure & Hosting Security
NoticeScale infrastructure is hosted in SOC2 Type II certified data centers. Our production systems feature automated multi-region daily backups, automated vulnerability scanning, and continuous uptime monitoring.
2. Passwordless & SSO Authentication
We support secure passwordless Magic Link authentication, Okta SAML 2.0, and Azure AD SSO integration for Enterprise customers to eliminate password reuse vulnerabilities.
3. Vulnerability Management & Bug Bounty
We run continuous dependency audits using GitHub Dependabot and conduct quarterly third-party penetration testing. Security researchers can report vulnerabilities to security@noticescale.com.