Security Center
SUPPORT · EXPERTINI ATS

Security Center

How data is protected on Expertini ATS, and how to report a security issue responsibly.

2 min de lectura · Actualitzat el juliol de 2026 · Editorial d'Expertini

This page covers the security practices relevant to a recruiter or hiring organisation evaluating the platform, and the responsible-disclosure process for reporting a vulnerability.

01Infrastructure

Expertini ATS runs on infrastructure operated directly by Expertini (not a resold third-party SaaS), on a dedicated Elasticsearch cluster with TLS in transit. Payment data is handled entirely by Stripe — card details never touch Expertini's own servers.

02Access control

Organisation data is strictly scoped by org_id at the data layer — one hiring organisation cannot query or view another's candidates, jobs, or applications. Within an organisation, owner/admin/recruiter roles control who can do what (e.g. only owners/admins can delete a client record in Client CRM).

03PII handling

Personal identifiers are pattern-stripped from CV text before any AI scoring step reads it — see the Privacy Policy for the full detail on what's stripped and the limits of that process.

04Responsible disclosure

Found a security vulnerability? Email security@expertini.com with reproduction steps. Please report privately before any public disclosure, and avoid accessing or modifying data beyond what's needed to demonstrate the issue — we don't currently run a paid bug-bounty program but do acknowledge good-faith reports.

05Data retention and deletion, concretely

Candidate application data is deleted automatically after 24 months — a scheduled process, not a request-only right the candidate has to know to exercise. Organisation secrets configured for integrations are stored server-side and never re-rendered back to a browser: once saved, the interface shows only that a credential exists, not its value. Payment card data never exists on Expertini systems at any point — the entire card lifecycle happens inside Stripe. The Privacy Policy is the authoritative statement of retention periods and data-subject rights; this page's job is the security-relevant summary.

06Answers to the questions security reviewers actually ask

For teams running a vendor security assessment, the short versions: tenant isolation is enforced at the data layer on every query (org-scoped filtering, not application-code convention alone). Role-based access separates owner/admin actions (billing, seats, deletion) from day-to-day recruiter work. Candidate PII is pattern-stripped before CV text reaches any AI processing step — the AI evaluates evidence, not identity, as detailed on the AI technology page. Transport is TLS; infrastructure is operated directly by Expertini rather than resold. And the scoring pipeline's decisions are reproducible and logged with dimension-level rationale — relevant to security reviews that now include algorithmic-accountability questions. For anything this summary doesn't cover, security@expertini.com answers assessment questionnaires directly.

Preguntes freqüents

Is there a paid bug bounty?
Not currently — stated plainly rather than implied otherwise. Good-faith reports are acknowledged and acted on, and private-first disclosure is the one firm ask.
Can Expertini staff see our candidate data?
Operational access is limited to what running and supporting the service requires — there's no cross-tenant browsing interface, and org-scoped filtering applies at the data layer, not just in the UI.
Who fills in our vendor security questionnaire?
Send it to security@expertini.com. The sections above cover the most common questions (isolation, retention, payment handling, AI data flow) if you need answers before a formal review.

D'un cop d'ull

  • Org data strictly scoped by org_id — no cross-organisation visibility
  • Card details handled entirely by Stripe, never stored by Expertini
  • PII pattern-stripped before any AI scoring step
  • Responsible disclosure via security@expertini.com, report privately first
  • 24-month automatic candidate-data deletion, scheduled not request-only
  • Integration secrets never re-rendered to the browser after saving

Vegeu security center en la vostra pròpia contractació.

Porteu una descripció d'oferta real a una demostració de 30 minuts: prova gratuïta inclosa.

Reserva una demostració
Expertini AI
En línia ara
Hola! Sóc l'expert en productes d'intel·ligència artificial d'Expertini. Pregunteu-me qualsevol cosa sobre les nostres solucions, obteniu orientació sobre qualsevol de les nostres eines de contractació o simplement digueu-me què esteu intentant fer: us indicaré la direcció correcta. Per a problemes específics del compte, envieu un correu electrònic a support@expertini.com.