Candidly

Security built into everything we do.

Protecting customer and candidate data is fundamental to our platform. From secure infrastructure and access controls to data privacy and ongoing monitoring, security is considered at every stage of development and delivery.

The integration handshake

Encryption instead of friction.

Integration is secure without adding unnecessary steps for your users.

The handshake is designed to protect every call into Candidly. Instead of relying on long-lived plaintext secrets, requests are encrypted, time-limited and authenticated per call.

Secure Payload Encryption

JWE RSA-OAEP + A256GCM

Payloads are encrypted end-to-end using industry-standard JWE encryption, ensuring secure data exchange and protection during transmission and processing.

TTL ≤ 60s

Short-lived tokens

Authentication tokens expire within a tightly controlled window, reducing replay risk if credentials are intercepted during transmission.

Fresh · Per-call

Per-request authentication

Every API call carries a freshly generated single-use token, preventing long-lived secrets from being exposed, leaked, or reused.

TLS 1.3

HTTPS enforced

All endpoints require HTTPS, protecting data in transit and refusing plaintext requests before they reach the application layer.

Defense in depth

What happens
under the surface?

Server-side controls protect the infrastructure: AWS firewalling, DDoS mitigation, IAM, encrypted backups. Application-side controls protect the runtime: authentication, RBAC, CSRF, input validation. The UFW bridges both.

Server-side

Infrastructure

  • AWS Firewall

    NETWORK

    Filters traffic to and from our network against predefined rules. Layered defences with automated threat detection.

  • AWS DDoS Protection

    AVAILABILITY

    Dynamically scales resources to neutralise volumetric attacks in real time. Platform stays available during onslaughts.

  • Security Groups

    NETWORK

    Virtual firewalls regulating inbound and outbound traffic on every server instance. Least-privilege rules, dynamic updates.

  • Uncomplicated Firewall (UFW)

    NETWORK

    Frontline mechanism filtering ingress/egress on the server itself. Customisable rules + logging for incident detection.

  • IAM (Identity & Access Mgmt)

    ACCESS

    Granular access controls tailored to user roles. Centralised user management with seamless identity-provider integration.

  • Two-Factor Authentication

    ACCESS

    Server accounts require password + secondary factor (mobile app code or hardware token). Mitigates credential-based attacks.

  • Disaster Recovery & Backups

    AVAILABILITY

    Recovery targets: RTO of 1 hour, RPO of approximately 5 minutes. Encrypted backups are retained for 90 days.

  • Monitoring & Alerts

    OBSERVABILITY

    Real-time infrastructure monitoring with automated alerts and proactive incident detection through AWS CloudWatch and related monitoring services.

  • Availability SLA

    AVAILABILITY

    99.9% platform availability, measured monthly.

  • Breach Notification

    RESPONSE

    Confirmed or suspected breaches affecting partner or candidate data are notified within 24 hours.

  • Data Residency

    RESIDENCY

    Partners can select their AWS region. Production, staging, backups and logs are all held within that region.

Application-side

Application

  • NextJS Authentication

    AUTH

    Robust user authentication and authorisation. Only authenticated users access privileged functionality and data.

  • Two-Factor Authentication

    AUTH

    OTP delivered by email after password entry. Enforced for all administrative users.

  • CSRF Token Protection

    SESSION

    Unique per-session tokens validate every request, preventing forged actions against trusted user sessions.

  • Role-Based Access Control

    RBAC

    Six distinct roles with tailored permissions, from Candidly Admin down to Agency. Admin-assigned, scope-limited.

  • Application Logging

    OBSERVABILITY

    Ruby on Rails logs capture errors, performance traces, and audit events for debugging and security review.

  • Application Alerts

    OBSERVABILITY

    Anomaly detection within the application surface. Stakeholders notified via Slack and email on suspicious activity.

  • Input Sanitisation / XSS Protection

    PROTECTION

    Strict input validation, output encoding, and protection against injection and cross-site scripting (XSS) attacks.

  • Data Retention & Deletion Controls

    PRIVACY

    Configurable data retention policies, with data deleted from live systems within 30 days of the service ending and from backups within 90 days.

  • Consent & Privacy Controls

    PRIVACY

    Privacy-focused data handling with user consent management aligned to GDPR compliance requirements.

  • Secrets Management

    ACCESS

    Secure storage, access control of API keys, database credentials, and authentication tokens.

Role-based access

Role-based access control

Every user sits within a predefined role, with permissions scoped to the work they need to do. Partner Super Admins, Client Account Owners, Reviewers, External Recruiters - permissions can be tailored to ensure users only see and do what's relevant to their role.

  • Partner Super Admin

    Manage platform operations including client onboarding, content oversight, and report generation. Extensive access for all user-management tasks.

  • Client Account Owner

    Primary authority on the client side. Full access to all reports and notifications; platform-wide visibility for the partner organisation.

  • Client Admin

    Oversees recruitment processes: job listings, candidate profiles, career page customisation. Full reporting tools and integration management.

  • Client User

    Actively engages in recruitment: manages jobs, candidates, and personal integrations. Access to reports and notifications relevant to their tasks.

  • Client Reviewer

    Focused on candidate evaluation. Only sees assigned jobs; participates in interviews and provides scorecard feedback.

  • External Recruiter

    Submits candidate applications on jobs shared with them. No access to client data outside the explicit job invite.

Auth & Security

Production-grade security,
white-labelled for you.

Account Security

User accounts are protected with authentication controls, optional two-factor verification, and safeguards against suspicious activity.

Access Controls

Role-based permissions keep users within defined boundaries, from partner super admins to hiring managers and external recruiters.

Data Encryption

Data is encrypted in transit and at rest, with HTTPS enforced across platform access and integration points. Passwords are hashed with bcrypt.

Protection Against Abuse

Firewalling, DDoS protection, session controls, and application alerts help detect and reduce unusual or suspicious activity.

GDPR Compliance

Candidly supports responsible data handling with configurable retention, access controls, and deletion workflows.

Secure File Handling

Documents uploaded to Candidly are stored securely, with controls in place to protect candidate, employee and onboarding files.

Independently verified · Certificate renewed annually

Annual CREST-Certified Penetration Testing

To help maintain a strong security posture, our platform is independently penetration tested each year by a CREST-accredited security consultancy. Findings are reviewed and remediated as part of our ongoing security programme.

Get in touch

Security where you need it.

Get clarity on permissions, data protection, GDPR compliance or platform security. We’ll help your team understand the controls behind the platform and the security model supporting your embedded hiring experience.

Talk to us