Trust

Security

The security controls and shared responsibilities that protect HireEGG accounts, application data, and enterprise workflows.

Applies to
Customers, security reviewers, users, and procurement teams.
Effective
July 17, 2026
Document
Operational policy · 2026.07
Browse all policies

01

Security approach

HireEGG applies risk-based controls across application development, authentication, authorization, data handling, logging, vendor selection, and incident response. This page describes the current baseline; a signed enterprise agreement may include additional commitments.

02

Identity and access

  • Managed authentication and session handling for user accounts.
  • Role and ownership checks intended to separate learner, candidate, recruiter, organization, and administrative actions.
  • Least-privilege access for operational data and restricted use of privileged service credentials.
  • Server-side validation for protected actions rather than relying only on interface controls.

03

Data protection

  • HTTPS and transport encryption for production web and provider connections that support it.
  • Provider-managed protections for stored database and object data.
  • Secrets supplied through environment configuration instead of public client code.
  • Sensitive values excluded or redacted from application logs and API responses where they are not required.
  • Retention and deletion controls designed around account, campaign, contract, security, and legal needs.

04

Application and API controls

The application uses input validation, authorization checks, security headers, restricted cross-origin access, rate limits on sensitive authentication actions, generic client errors, and server-side handling for privileged provider calls. Controls are reviewed as the product changes.

05

Monitoring and incident response

Security and operational events may be logged to detect abuse, investigate failures, support incident response, and preserve evidence. HireEGG assesses suspected incidents, contains impact, coordinates with affected providers or customers, and gives legally or contractually required notice.

06

Service providers

HireEGG evaluates providers in relation to their function and limits the data sent to what that function needs. Provider names and purposes are listed on the Subprocessors page. Enterprise customers should complete their own risk review before enabling sensitive campaigns.

07

Shared responsibility

Customers and users must protect credentials, configure roles and campaigns carefully, review exports and reports before sharing them, use supported devices, report suspicious activity, and comply with applicable employment and privacy requirements. Security depends on both platform controls and customer operation.

08

Assurance and contact

No control makes a service immune from risk, and this page is not a certification or guarantee. Procurement teams can request current evidence and contractual commitments. Security concerns should be reported under the Responsible Disclosure policy or sent to info@hireegg.com.

Questions about this document?

Enterprise customers can also request a signed DPA, security review, or procurement materials.

info@hireegg.com