Security

Candidate and employee data - handled seriously, described honestly.

Ramp-up data is sensitive. It touches candidates who did not get the offer, hires who are still finding their feet and managers who need honest signals. Clorrior treats every one of those categories accordingly.

Encryption in transit

All traffic is served over TLS. No user data ever moves in cleartext between browser, servers or integrations.

Encryption at rest

Persistent data is encrypted at rest at the storage layer. Backups inherit the same encryption posture.

Role-based access

HR, hiring manager and new-hire views are separate by design. A view returns only what that role is authorised to see.

Audit trail

Sensitive actions - access grants, gap edits, training assignments - are logged and reviewable inside the same system.

Least-privilege integrations

Calendar, ATS and HRIS integrations use the narrowest scopes needed - not blanket read/write to everything.

Incident readiness

Documented process for detection, containment and communication - covered in the terms and expanded during Enterprise onboarding.

Data lifecycle

What is collected, why, and for how long.

Candidate data

Only what the loop needs

Scheduling availability, interview outcomes and feedback captured through invited panels. Not scraped, not sold.

Retained for the loop plus the retention window agreed with the customer.

New-hire data

Only what the ramp needs

Task state, review feedback signals and self-assessment responses. Not keystrokes, not clicks, not browsing.

Retained for the ramp window plus the customer's HR record policy.

Aggregate data

Only what the curve needs

Team ramp velocity and historical baselines are computed at the customer level - never shared across customers.

Retained as long as the customer relationship is active.

Compliance posture

Where we are today - stated plainly.

In place today

  • TLS on all traffic; encryption at rest at the storage layer
  • Role-based access model separating HR, manager and new-hire views
  • Audit trail on sensitive changes to hire records
  • Data-processing terms available at contract time

Roadmap - openly listed

  • Independent security audit and public report
  • Regional data-residency options for Enterprise customers
  • Extended SSO options and SCIM provisioning
  • Formal SOC posture as customer footprint requires

We list what is in place and what is on the roadmap plainly, rather than implying certifications that are not yet earned.

Security review before you commit?

For Enterprise-tier evaluation, contact sales for a security review packet and a working session with our team.