Candidate and employee data - handled seriously, described honestly.
Ramp-up data is sensitive. It touches candidates who did not get the offer, hires who are still finding their feet and managers who need honest signals. Clorrior treats every one of those categories accordingly.
Encryption in transit
All traffic is served over TLS. No user data ever moves in cleartext between browser, servers or integrations.
Encryption at rest
Persistent data is encrypted at rest at the storage layer. Backups inherit the same encryption posture.
Role-based access
HR, hiring manager and new-hire views are separate by design. A view returns only what that role is authorised to see.
Audit trail
Sensitive actions - access grants, gap edits, training assignments - are logged and reviewable inside the same system.
Least-privilege integrations
Calendar, ATS and HRIS integrations use the narrowest scopes needed - not blanket read/write to everything.
Incident readiness
Documented process for detection, containment and communication - covered in the terms and expanded during Enterprise onboarding.
What is collected, why, and for how long.
Only what the loop needs
Scheduling availability, interview outcomes and feedback captured through invited panels. Not scraped, not sold.
Retained for the loop plus the retention window agreed with the customer.
Only what the ramp needs
Task state, review feedback signals and self-assessment responses. Not keystrokes, not clicks, not browsing.
Retained for the ramp window plus the customer's HR record policy.
Only what the curve needs
Team ramp velocity and historical baselines are computed at the customer level - never shared across customers.
Retained as long as the customer relationship is active.
Where we are today - stated plainly.
In place today
- TLS on all traffic; encryption at rest at the storage layer
- Role-based access model separating HR, manager and new-hire views
- Audit trail on sensitive changes to hire records
- Data-processing terms available at contract time
Roadmap - openly listed
- Independent security audit and public report
- Regional data-residency options for Enterprise customers
- Extended SSO options and SCIM provisioning
- Formal SOC posture as customer footprint requires
We list what is in place and what is on the roadmap plainly, rather than implying certifications that are not yet earned.
Security review before you commit?
For Enterprise-tier evaluation, contact sales for a security review packet and a working session with our team.