Data Security
Last updated: August 1, 2026
1. Security Overview
Empikalyze is designed with security as a core consideration from the ground up. Our practices are built according to recognized industry best practices for protecting sensitive customer and candidate data, including encryption, strict access control, and continuous monitoring.
We implement multi-tenant isolation so that each customer organization operates within its own isolated workspace. Your organization's data is never shared with, or accessible by, other organizations on the platform.
We follow the principle of least privilege, ensuring that each user, service, and component has only the minimum access required to perform its function.
2. Data Encryption
Encryption in Transit
All data exchanged between your browser and Empikalyze is protected using TLS/HTTPS encryption. This ensures that resumes, job descriptions, analyses, and authentication traffic cannot be intercepted or read while moving across networks.
We enforce HTTPS across the entire application and require modern, industry-standard transport security for every connection.
Encryption at Rest
All customer data—including uploaded resumes, job descriptions, screening results, and account information—is encrypted at rest using industry-standard encryption mechanisms.
This ensures that even if physical storage were compromised, your data would remain unreadable without the appropriate encryption keys.
Secure Document Storage
Uploaded resumes and customer documents are stored using encrypted cloud storage infrastructure with appropriate access controls. Access to stored files is restricted to authorized services and scoped to your organization only.
3. Authentication & Authorization
Secure Authentication
Authentication is managed by a dedicated, hardened authentication provider using secure, industry-standard mechanisms. We do not store plaintext passwords—credentials are protected using modern hashing and secure session handling.
Session tokens are short-lived and automatically refreshed to minimize exposure, and account access can be revoked immediately when needed.
Secure Password Handling
Passwords are never stored in readable form. We apply strong, industry-standard password hashing and validate password strength during signup and password reset to reduce the risk of compromised credentials.
Role-Based Access Control
Access to your data is controlled through role-based access control (RBAC). Within each organization, administrators and recruiters can only access the data and features relevant to their role.
Organization administrators can manage user permissions and team membership centrally, ensuring appropriate access levels at all times.
Workspace & Organization Isolation
Every customer organization operates within a single, isolated workspace. All recruiters within your organization share one quota pool and work inside that isolated boundary. Data from your organization is never visible to or accessible by other organizations on the platform.
Database Row-Level Security
Access to records is enforced at the database layer using Row-Level Security (RLS). This means data access is constrained by your authenticated identity and organization membership—not merely by application logic—providing defense-in-depth against unauthorized data exposure.
Internal Access Restrictions
Empikalyze personnel have no direct access to customer production data without explicit authorization, and internal access is logged for support and maintenance cases. Administrative actions follow the principle of least privilege.
4. AI Processing Security
Empikalyze uses AI to analyze and rank resumes. All AI processing is performed within controlled, access-restricted environments designed to protect customer data:
- Access-controlled processing: AI processing runs only against authorized requests and scoped data tied to your organization.
- No memorization: Resume content is processed transiently for generating results and is not used to build persistent training datasets.
- No cross-customer leakage: AI processing and inference are logically isolated per customer to prevent cross-organization data access.
- Contextual output, not storage: AI output is generated based on your resume and job description context. The output is contextual and is not used to train shared models.
5. Payment Security
Secure Payments via Razorpay
All payments are processed by Razorpay, a PCI-DSS compliant payment gateway. Empikalyze does not collect, process, or store full card numbers or other sensitive payment instrument details on its own servers.
Payment integrity is verified through signed callbacks and webhook signature validation, ensuring that quota is granted only for genuinely confirmed and verified transactions.
6. Monitoring, Logging & Recovery
Monitoring and Logging
Empikalyze monitors application activity and key security events to detect anomalies, errors, and potential misuse. Operational logs are retained to support accountability, troubleshooting, and incident investigation.
Backups and Disaster Recovery
Customer data is protected by managed backups and disaster-recovery capabilities provided by our underlying infrastructure. These measures are designed to support recovery and business continuity in the event of infrastructure failure or data loss.
Security Updates
We apply security patches and dependency updates on an ongoing basis to address known vulnerabilities and reduce risk. Security-relevant changes are reviewed before being released to production.
7. Incident Response
We take security incidents seriously and follow a structured response process:
- Security incidents are handled with high priority and escalated to appropriate teams immediately.
- Affected customers are notified without undue delay when an incident involves their data.
- We conduct post-incident reviews to understand root causes and implement preventive measures.
8. Compliance Positioning
Empikalyze is designed with recognized data protection principles in mind:
- Privacy by design: Our approach aligns with widely recognized data protection principles including data minimization, purpose limitation, and user rights.
- India regulatory awareness: We are aware of India's Information Technology Act and the Digital Personal Data Protection (DPDP) requirements.
- Best-practice focus: Our security practices are designed according to industry best practices for SaaS data protection.
Important: Empikalyze is designed with security and privacy best practices, but we do not currently hold formal certifications such as ISO 27001, SOC 2, HIPAA, GDPR certification, or PCI certification. Payment processing itself is handled by our PCI-DSS compliant payment gateway partner.
9. Responsible Security Disclosure
We welcome and encourage responsible disclosure of security vulnerabilities. If you believe you have identified a security issue in Empikalyze, please report it to us privately rather than publicly disclosing it.
We are committed to acknowledging valid reports promptly and working with researchers to resolve issues responsibly.
10. Contact
For security inquiries, vulnerability reports, or compliance questions, please contact us at security@empikalyze.in.