We protect your privacy and make vigilant efforts to protect all your data. We would never do anything with your data that we wouldn't be proud to tell the world about, and we treat all data sent to AblyWorks with the utmost diligence to ensure it is handled securely. Whether it's candidate resumes, employee records, sales pipelines, or access credentials, we promise to keep it private and secure.
AblyWorks operates a defense-in-depth security model across every layer of our organization—from our cloud infrastructure and deployment pipelines to internal employee access protocols. Our architecture is designed to guarantee high availability, continuous data integrity, and strict confidentiality.
Core Operational Security Pillars
Corporate Governance
Executive and board-level oversight of our business integrity, customer privacy standards, and regulatory compliance programs.
Change Management
Strict peer-reviewed pull requests, automated security linting, and staged deployment pipelines for all codebase updates.
Access Management
Role-Based Access Control (RBAC), Least-Privilege principle, Multi-Factor Authentication (MFA), and automated credential rotation.
Data Redundancy & Backups
Multi-zone redundant database replication, automated hourly snapshots, and point-in-time recovery to eliminate data loss.
Secure SDLC
Continuous vulnerability scanning (SAST/DAST), third-party penetration audits, and OWASP Top 10 mitigation built into development.
Continuous Monitoring
24/7 automated telemetry, audit log tracking, intrusion detection, and immediate anomaly alerts across all production servers.
AblyWorks is built to adhere to the rigorous SOC 2 (System and Organization Controls) Trust Services Criteria established by the American Institute of Certified Public Accountants (AICPA). We undergo regular evaluations to demonstrate our security posture and operational integrity.
The SOC 2 framework offers independent verification that our systems offer a comprehensive spectrum of security measures. The audit covers internal governance, production operations, change management, data backups, and software development processes—providing assurance that appropriate controls and procedures are in place and functioning effectively.
Scope of Trust Services Criteria
- Security (Common Criteria): Protection of system resources against unauthorized access, malicious vulnerability exploits, and data exfiltration.
- Availability: Accessibility of our services for operation and use as committed by our 99.9% uptime Service Level Agreement (SLA).
- Confidentiality: Protection of information designated as confidential from disclosure to unauthorized parties or sub-systems.
- Processing Integrity: Delivery of complete, valid, accurate, timely, and authorized system processing and algorithm execution.
All customer data is encrypted both in transit over public networks and at rest within our production databases, file storage clusters, and backup volumes.
Encryption in Transit
All network communications between your web browsers, mobile endpoints, API integrations, and AblyWorks servers are strictly enforced over HTTPS with TLS 1.3 / TLS 1.2 encryption using modern forward-secrecy cipher suites. Unencrypted HTTP requests are automatically upgraded and redirected.
Encryption at Rest
All database records, candidate resumes, parsed documents, communication logs, and automated disaster recovery backups are encrypted at rest using industry-standard AES-256 (Advanced Encryption Standard with 256-bit keys). Encryption keys are managed through dedicated Key Management Systems (KMS) with automatic annual rotation.
Personally Identifiable Information (PII) Protection
AblyWorks de-identifies and redacts sensitive data whenever possible, and implements access control whenever necessary, with all sensitive information encrypted by default. Features ensure that only authorized team members with granular permission levels can view or export candidate or employee personal data.
This AblyWorks Data Processing Agreement and its Annexes ("DPA") reflects the parties' agreement with respect to the Processing of Personal Data by AblyWorks on behalf of you or your organization ("Customer") in connection with the AblyWorks Services under the AblyWorks Terms of Service.
This DPA is supplemental to and forms an integral part of the Agreement between the parties. In case of any conflict or inconsistency between the terms of the Agreement and this DPA, the terms of this DPA will take precedence with respect to the Subject Matter of Personal Data Processing.
Key DPA Commitments
- Controller & Processor Roles: Customer acts as the Data Controller with full ownership of data, and AblyWorks acts strictly as the Data Processor processing data solely under Customer's documented instructions.
- Confidentiality Obligations: All AblyWorks personnel authorized to process Customer Data are bound by strict non-disclosure obligations and undergo mandatory regular data security training.
- Data Subject Rights Assistance: AblyWorks provides built-in tools and API endpoints to help Customers fulfill their obligations to respond to data subject requests (access, rectification, restriction, erasure, and portability).
- Data Return & Deletion: Upon termination or expiration of your subscription, AblyWorks will securely delete or return all Customer Data within 30 days, in accordance with industry sanitization standards (NIST 800-88).
For the purposes of this Security & Data Processing document, the following standardized privacy terms shall have the meanings set forth below:
"California Personal Information"
Personal Data that is subject to the protection of the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act (CPRA).
"Controller" & "Processor"
"Controller" means the legal entity which determines the purposes and means of Processing. "Processor" means the entity which processes Personal Data on behalf of the Controller.
"Data Protection Laws"
All applicable worldwide legislation relating to data protection and privacy, including the EU General Data Protection Regulation (GDPR), UK GDPR, CCPA/CPRA, and relevant national data privacy acts.
"Personal Data Breach"
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed by AblyWorks.
"Sub-processor"
Any authorized third party engaged by AblyWorks to assist in fulfilling its processing obligations with respect to providing the AblyWorks platform services.
AblyWorks partners with tier-1 cloud service providers and infrastructure leaders to deliver maximum scalability, security, and uptime. All sub-processors undergo comprehensive vendor risk evaluations and execute Data Processing Agreements with Standard Contractual Clauses (SCCs).
Amazon Web Services (AWS)
Primary Cloud Hosting & Compute
US / EU / APAC Regions
Cloudflare
DDoS Protection, WAF & Global CDN
Global Edge Network
SendGrid / Twilio
Transactional Email & SMS Relays
United States
OpenAI API
Enterprise AI & Resume Parsing
Zero-Data Retention Tier
* Note: We enforce zero-data retention on enterprise AI integrations, ensuring your candidate and business data is never used to train foundational AI models.
Security is a shared partnership between AblyWorks (as the SaaS solution provider) and your organization (as the tenant). Here is how responsibilities are distributed:
| Security Dimension |
AblyWorks Responsibility |
Customer Responsibility |
| Data Center & Cloud |
Physical security, compute isolation, hypervisor patching |
None (Fully managed by AblyWorks) |
| Platform Encryption |
TLS 1.3 HTTPS in transit & AES-256 database at rest |
Secure local network & modern browser usage |
| User Authentication |
Password hashing (bcrypt), MFA framework, session timeouts |
Enforcing strong passwords & enabling MFA for all staff |
| Access Governance |
Granular Role-Based Access Control (RBAC) engine |
Assigning appropriate permissions & offboarding former employees |
| Data Backup & DR |
Automated hourly snapshots, multi-region failover |
Routine data verification & maintaining local audit archives |