We are committed to protecting the security and privacy of your data. This policy outlines our comprehensive security measures.
1. Introduction
At BorderLess, security is our top priority. This Security Policy outlines the technical and organizational measures we implement to protect your data from unauthorized access, disclosure, alteration, and destruction.
2. Data Encryption
We employ industry-standard encryption to protect your data:
TLS/SSL encryption for all data in transit between your browser and our servers
AES-256 encryption for sensitive data at rest in our databases
Encrypted backups stored in geographically distributed locations
3. Access Controls
We implement strict access controls to ensure only authorized personnel can access your data:
Role-based access control (RBAC) limiting data access to specific user roles
Multi-factor authentication (MFA) required for administrative access
Regular access audits and automatic session timeouts
Principle of least privilege for all system access
4. Infrastructure Security
Our infrastructure is built with security in mind:
Cloud hosting with enterprise-grade security providers
Firewalls and intrusion detection systems monitoring all network traffic
Regular security patches and updates to all systems
Isolated development, staging, and production environments
5. Application Security
We follow secure development practices throughout our software lifecycle:
Regular code reviews and security testing
Protection against common vulnerabilities (SQL injection, XSS, CSRF)
Automated security scanning in our CI/CD pipeline
Third-party security audits and penetration testing
6. Data Backup and Recovery
We maintain comprehensive backup and disaster recovery procedures. All data is automatically backed up daily with encrypted storage in multiple geographic locations. We regularly test our recovery procedures to ensure business continuity.
7. Incident Response
We have a formal incident response plan to address potential security incidents:
24/7 security monitoring and alerting systems
Immediate investigation and containment of security incidents
Notification to affected users within 72 hours of confirmed breaches
Post-incident analysis and implementation of preventive measures
8. Employee Training
All employees receive comprehensive security training, including data handling best practices, phishing awareness, and incident reporting procedures. Security training is mandatory and conducted regularly.
9. Third-Party Security
We carefully vet all third-party service providers and require them to maintain security standards comparable to our own. All third-party integrations are reviewed for security compliance before implementation.
10. Compliance
We maintain compliance with relevant security standards and regulations:
GDPR (General Data Protection Regulation) compliance for EU users
SOC 2 Type II compliance (in progress)
Industry-specific regulations applicable to recruitment and HR data
11. Your Responsibilities
While we implement robust security measures, security is a shared responsibility. Please:
Use strong, unique passwords and enable multi-factor authentication
Keep your account credentials confidential
Report suspicious activity or security concerns immediately
Ensure your devices and network connections are secure
If you discover a security vulnerability, please report it responsibly to help us protect all users.
12. Reporting Security Issues
If you identify a potential security vulnerability or incident, please report it immediately to our security team. We appreciate responsible disclosure and will acknowledge receipt within 24 hours.
We continuously improve our security measures and will update this policy as needed. Significant changes will be communicated through our platform and via email.