Security Architecture &
Data Protection Whitepaper.
Last Updated: January 2026. This comprehensive whitepaper outlines the 10 technical, cryptographic, operational, and organizational security pillars protecting Ascent and our recruitment agency clients worldwide.
In-Transit Encryption
TLS 1.3 Strict
At-Rest Storage
AES-256 Bit
DPDP Consent
SHA-256 Ledger
Breach SLA
≤ 72 Hours
Organizational & Personnel Security
Security at Ascent begins with strict internal governance. All personnel with system access are bound by non-disclosure agreements, least-privilege role boundaries, and regular security awareness assessments.
All employees and contractors undergo third-party identity, criminal history, and credential verification prior to onboarding.
Access to production systems is granted strictly on a need-to-know basis and requires multi-factor authentication.
100% of staff sign legally binding non-disclosure covenants guaranteeing zero disclosure or commercialization of customer recruitment data.
Workstations run encrypted drives (BitLocker/FileVault), mandatory idle lockouts, and up-to-date operating system security patches.
Physical Security & Data Sovereignty
We believe recruitment data belongs to the agency. We provide both localized cloud infrastructure and 100% air-gapped offline desktop capabilities to eliminate unauthorized physical or cloud data exposure.
The Ascent Desktop app binds strictly to local loopback (127.0.0.1), keeping candidate resumes completely offline on your office LAN.
Cloud production workloads are hosted within high-security enterprise data centers located within Mumbai & Hyderabad regions with 24/7 biometric controls and CCTV.
No unencrypted third-party data broker or advertising cloud holds copies of your candidate resumes or placement financial records.
Infrastructure & Network Defense
Our cloud perimeter utilizes industry-standard edge firewalls, automated rate limiting, and strict security headers to defend against modern cyber threats.
All network traffic is encrypted using TLS 1.3 with Perfect Forward Secrecy (PFS) and strict HSTS (HTTP Strict Transport Security) preloading.
Strict Content-Security-Policy (CSP), X-Frame-Options (DENY), X-Content-Type-Options (nosniff), and Referrer-Policy prevent XSS and clickjacking.
Public API endpoints enforce sliding-window IP rate limits and bot honeypots to mitigate credential stuffing and DoS flooding attacks.
Data Security & Cryptographic Ledger
Ascent pioneers mathematical, cryptographic non-repudiation in recruitment software to ensure tamper-proof compliance with India's DPDP Act 2023 and the GDPR.
All database tables, candidate resumes, and financial rate cards are encrypted at rest using AES-256 cryptographic standards.
Every candidate consent interaction via WhatsApp or email generates an immutable SHA-256 digital fingerprint recording IP, timestamp, and purpose.
Application secrets and JWT signing keys are cryptographically separated from database storage with automated rotation.
Identity & Access Management (IAM)
Workstation defense is engineered with multi-tiered identity verification to prevent unauthorized access even in the event of compromised workstation credentials.
Dual-factor authentication enforces an in-house numeric PIN on workstation logins, sensitive system settings, and password recovery.
User credentials are protected using high-work-factor bcrypt hashing with real-time complexity validation (8+ chars, upper, lower, number, symbol).
Active sessions automatically invalidate upon conflicting logins from unrecognized devices to prevent credential sharing.
Session tokens are transmitted strictly via encrypted JWTs marked HttpOnly, Secure, and SameSite=Lax.
AI Privacy & Algorithmic Governance
Ascent integrates Google Gemini AI strictly as an ephemeral, assistive decision-support parser under enterprise privacy guarantees.
Customer resumes, notes, and rate cards are never used by Google or Ascent to train, fine-tune, or improve public AI foundation models.
Resume text snippets sent for semantic match scoring are processed in-memory over TLS 1.3 and discarded immediately upon response return.
Outbound AI requests utilize private x-goog-api-key header transport with automated log redaction to prevent secret leakage.
AI Match-Score serves strictly as an assistive tool; no autonomous hiring or rejection decisions occur without human recruiter oversight.
Operational Continuity & Disaster Recovery
Designed for high-velocity staffing agencies, our platform maintains continuous automated backups and resilient failover procedures.
Point-in-time database snapshots are taken automatically and stored with multi-region redundancy.
Real-time system health monitors track database connection pool health, V8 memory heap limits, and API response latencies.
Stateless App Router design ensures rapid container restarts and zero data corruption during deployment hot-reloads.
Incident Response & 72-Hour Breach SLA
We maintain a formalized incident response lifecycle to detect, contain, investigate, and notify stakeholders of potential security events.
In the unlikely event of a confirmed security incident impacting customer PII, affected account admins and regulatory authorities are notified within 72 hours.
Automated SRE alert rules trigger instant notifications upon abnormal login velocity or elevated error spikes.
Comprehensive root-cause analysis (RCA) documentation is provided following any critical severity incident.
Vulnerability Disclosure & Bug Bounty Safe Harbor
We welcome responsible security researchers and maintain a formal vulnerability disclosure program to identify and remediate emerging threats proactively.
Researchers conducting good-faith security testing within our guidelines are granted safe harbor against legal action.
Security reports submitted to our security desk receive an initial engineering response within 24 business hours.
Confirmed critical and high severity vulnerabilities are patched within expedited 24-48 hour hotfix cycles.
Customer Security Controls & Data Governance
We provide agency administrators with full sovereignty and self-service tools to manage access, audit activity, and honor candidate privacy rights.
Review detailed timestamped logs of every candidate profile view, resume export, role change, and client portal access.
Instantly process candidate Right to be Forgotten requests with 1-click permanent cryptographic profile scrubbing.
Export your entire talent pipeline, placement financials, and resume archive in standard CSV/JSON formats anytime with zero vendor lock-in.
Responsible Vulnerability Disclosure
Collaborating with ethical security researchers worldwide.
If you believe you have found a security vulnerability in Ascent, please submit a detailed report to our security engineering team. We prioritize vulnerability reports with rapid triage and grant safe harbor protection to ethical researchers.
Official Security Desk: admin@hiresoft.in
Legal Entity: Legion Hiresoft India Private Limited
Initial Triage SLA: Within 24 Business Hours
Security & Sovereignty by Design.
Ready to experience an ATS built with cryptographic DPDP consent receipts and air-gapped desktop sovereignty?