Legal

Security

How we protect the hiring data you trust us with, and how to report a problem.

Last updated: 30 September 2026

Hiring data is personal: resumes, pay, identity documents, interview notes. This page describes the controls that protect it in SuprHiro today. It is written for customers’ IT and security teams; our Data Processing Agreement makes these measures a contractual commitment.

1. Encryption

  • All traffic to SuprHiro is served over HTTPS.
  • The most sensitive fields are encrypted at rest with AES-256-GCM, each with its own random IV: PAN, Aadhaar, passport and bank account numbers; AI call and interview transcripts and summaries; email and chat messages; temporary passwords for new-hire email accounts; and credentials for connected calendar and WhatsApp accounts. In production the application refuses to start without its encryption key.
  • Identity and bank numbers collected during onboarding are never shown back in full — the application displays them masked.

2. Customer isolation

Every record belongs to one workspace, and every query is scoped to the signed-in user’s workspace; a request for another workspace’s record is answered as if it did not exist. New records are always stamped with the caller’s workspace, never one taken from the request. An automated test suite checks cross-workspace access.

3. Access control

  • Six built-in roles — admin, recruiter, hiring manager, interviewer, analyst and IT admin — plus custom roles, each with specific permissions. Recruiters see only candidates on their own jobs.
  • Only admins can buy plans; only admins and IT admins can see billing.
  • SuprHiro platform staff have read-only access to workspaces for support, cannot change customer data and cannot export it.
  • Candidates reach their pages through single-use, time-limited links; candidate portal links are valid for 15 minutes and stored only as a hash.

4. Sign-in

  • Passwords must be at least 12 characters with upper- and lower-case letters and a digit, and are stored only as bcrypt hashes.
  • Sign in with Google or LinkedIn is available.
  • Accounts lock after 5 failed attempts, and an IP address after 20, within 15 minutes.
  • Sessions expire after 8 hours, use HttpOnly and Secure cookies, and can be revoked.
  • New workspaces confirm their email address before use, and disposable email domains are refused.

5. Application security

  • Rate limits on sign-in, public forms, AI features and the API; the most sensitive limits fail closed.
  • CAPTCHA on signup and job application forms.
  • Checks on the origin of every state-changing request, plus CSRF protection.
  • Security headers that block framing and content sniffing, and restrict camera, microphone and location access.
  • Uploaded files can be scanned for malware on our own servers.
  • Instructions hidden in resumes are fenced off from the AI so they cannot redirect it.
  • Error reports are stripped of request bodies, cookies and credentials before they leave our servers.

6. Logging and monitoring

We keep an audit log of important actions — who did what, when, and from where — and of access to call records and messages. Sign-in attempts are recorded to detect attacks.

7. Vendors

We use a small number of established providers, listed with their purpose on our Sub-processors page. Payments are handled entirely by PayU; card and bank details never reach SuprHiro.

8. Incident response

If a security incident affects customer personal data, we notify affected workspace admins without undue delay and within 72 hours of becoming aware of it, and help them meet their own notification duties.

9. Reporting a vulnerability

Found a security issue? Email hiring@supahiro.co with the details and steps to reproduce it. Please give us reasonable time to fix it before disclosing it, do not access or change other people’s data, and do not run tests that degrade the Service (such as denial-of-service or spam). We will not take legal action against research carried out in good faith within these rules, and we will keep you updated as we fix the issue.

10. Security questionnaires

Customers and prospective customers can send security questionnaires to hiring@supahiro.co.