Security Policy

Effective Date: January 1, 2025

Last Updated: January 1, 2025


1. Introduction

At BorderLess, security is our top priority. This Security Policy outlines the technical and organizational measures we implement to protect your data from unauthorized access, disclosure, alteration, and destruction.

2. Data Encryption

We employ industry-standard encryption to protect your data:

  • TLS/SSL encryption for all data in transit between your browser and our servers
  • AES-256 encryption for sensitive data at rest in our databases
  • Encrypted backups stored in geographically distributed locations

3. Access Controls

We implement strict access controls to ensure only authorized personnel can access your data:

  • Role-based access control (RBAC) limiting data access to specific user roles
  • Multi-factor authentication (MFA) required for administrative access
  • Regular access audits and automatic session timeouts
  • Principle of least privilege for all system access

4. Infrastructure Security

Our infrastructure is built with security in mind:

  • Cloud hosting with enterprise-grade security providers
  • Firewalls and intrusion detection systems monitoring all network traffic
  • Regular security patches and updates to all systems
  • Isolated development, staging, and production environments

5. Application Security

We follow secure development practices throughout our software lifecycle:

  • Regular code reviews and security testing
  • Protection against common vulnerabilities (SQL injection, XSS, CSRF)
  • Automated security scanning in our CI/CD pipeline
  • Third-party security audits and penetration testing

6. Data Backup and Recovery

We maintain comprehensive backup and disaster recovery procedures. All data is automatically backed up daily with encrypted storage in multiple geographic locations. We regularly test our recovery procedures to ensure business continuity.

7. Incident Response

We have a formal incident response plan to address potential security incidents:

  • 24/7 security monitoring and alerting systems
  • Immediate investigation and containment of security incidents
  • Notification to affected users within 72 hours of confirmed breaches
  • Post-incident analysis and implementation of preventive measures

8. Employee Training

All employees receive comprehensive security training, including data handling best practices, phishing awareness, and incident reporting procedures. Security training is mandatory and conducted regularly.

9. Third-Party Security

We carefully vet all third-party service providers and require them to maintain security standards comparable to our own. All third-party integrations are reviewed for security compliance before implementation.

10. Compliance

We maintain compliance with relevant security standards and regulations:

  • GDPR (General Data Protection Regulation) compliance for EU users
  • SOC 2 Type II compliance (in progress)
  • Industry-specific regulations applicable to recruitment and HR data

11. Your Responsibilities

While we implement robust security measures, security is a shared responsibility. Please:

  • Use strong, unique passwords and enable multi-factor authentication
  • Keep your account credentials confidential
  • Report suspicious activity or security concerns immediately
  • Ensure your devices and network connections are secure

12. Reporting Security Issues

If you identify a potential security vulnerability or incident, please report it immediately to our security team. We appreciate responsible disclosure and will acknowledge receipt within 24 hours.

Security Email: info@borderlessats.com

13. Updates to Security Policy

We continuously improve our security measures and will update this policy as needed. Significant changes will be communicated through our platform and via email.