Your candidate information, hiring workflows, and communication records are protected with encryption, access controls, and continuous monitoring. We don't compromise on security, it's built into how we design and operate AblyWorks.
Across the AblyWorks platform, whether you use ATS, Reach, Remind, or our other products, your data receives the same protection and care.
We understand what's at stake. Your hiring data contains sensitive personal information, resumes, contact details, interview feedback, salary history. That information belongs to your candidates and your organization, and it's our responsibility to keep it safe.
Our approach to security is built on three core principles:
Privacy by Design
We minimize data collection, limit access, and build security into every new feature from day one.
Transparency
We're honest about our capabilities and limitations; we don't make unverifiable promises.
Accountability
We take ownership when things go wrong and fix them quickly.
Continuous Evolution: Security is never finished. Threats evolve, so our defenses evolve too. We invest in ongoing security improvements, monitoring, and vulnerability management because the stakes are too high not to.
How We Protect Customer Information
Data Safeguards
Encryption
Sensitive data in transit and at rest is encrypted using industry-standard encryption protocols. This includes candidate information, resumes, communication records, and any personal data stored within AblyWorks products.
We use:
TLS 1.2 or higher: For all data in transit across public and internal networks
Encryption at rest: For sensitive fields, database storage, and document repositories
Secure key management practices: Robust key generation, storage, and strict separation of duties
Access Control
Not everyone on our team has access to customer data. We follow the principle of least privilege, people only get access to the data and systems they need to do their specific job.
This means:
Role-based access controls: Enforced across our platform, application layers, and underlying infrastructure
Multi-factor authentication (MFA): Required for all employee access to production systems and internal tools
Regular access reviews: Periodic audits of who has access to what, ensuring continuous compliance
Immediate revocation: Automated and strict offboarding processes when employees leave the organization
Data Retention & Deletion
You control your data. You can:
Export your data: Retrieve candidate and hiring data at any time in structured formats
Delete candidate records: Remove applicant files according to your organization's retention policies
Request organizational deletion: Permanently request the deletion of your organization's entire data footprint
When you delete data through AblyWorks, it's removed from our active systems. Deleted data may remain in backups for a limited period, then is permanently destroyed.
Application Security
Code & App Protection
Secure Development Practices
Our engineering team builds security into code from the start, not as an afterthought.
Code reviews: Conducted on all changes to catch potential security issues before code goes live
Security-focused training: Continuous training for our engineering and product teams on modern security standards
Vulnerability testing: Regular testing and auditing for common web application vulnerabilities (such as OWASP Top 10)
Dependency management: Automated vulnerability monitoring to keep all third-party libraries and frameworks updated
Vulnerability Management
If a vulnerability is discovered, we follow a clear, rapid-response process:
1
Assessment
We immediately evaluate the risk, scope, and potential impact.
2
Fix
Our engineering team works to develop, review, and test a fix.
3
Deployment
We release the fix directly to our production systems.
4
Communication
We inform affected customers with complete transparency if necessary.
We take security issues seriously, and our team prioritizes fixes based on severity and real-world risk.
Third-Party Security
The tools and services we depend on are vetted for security. This includes:
Cloud infrastructure providers: Scalable, tier-1 data center environments
Email delivery services: Secure, authenticated communication relays
Analytics and monitoring tools: Anomaly detection and platform telemetry systems
We review security practices of our vendors and maintain agreements that protect customer data.
Data Privacy
Privacy & Compliance
What Data We Collect
AblyWorks collects and processes information necessary to operate the platform:
Account information: Organization details, team profiles, and user login credentials
Recruitment data: Candidate profiles, resumes, and application information
Hiring records: Communication logs, interview schedules, and hiring workflow data
Usage telemetry: Aggregate usage metrics to improve platform reliability and performance
Our Promise on Your Data: We don't sell your data to third parties. We don't use your hiring data to build competing products or train AI models without your permission.
How Long We Keep Data
Data retention depends on your account status and configuration:
Active account data: Retained for as long as you actively use AblyWorks
Post-deletion data: After account deletion, most data is removed within 30 days
Legal & operational records: Some data may be retained longer for legal or operational reasons (backup recovery, audit logs)
International Data Transfers
If your organization is located outside the United States, we comply with applicable data protection laws regarding international data transfers.
Infrastructure & Reliability
High Availability
Uptime & Availability
We design and operate our infrastructure for reliability. Downtime impacts your hiring process, so we take availability seriously.
Our platform is built on infrastructure designed to be resilient. We monitor performance continuously and maintain backup systems to minimize disruption.
Monitoring & Incident Response
We maintain 24/7 monitoring of our systems. If something goes wrong:
Immediate alerting: Our engineering team is alerted immediately upon anomaly detection
Severity-based response: We investigate and respond according to incident severity
Customer communications: We communicate status to customers if there's any operational impact
Transparent post-mortems: We publish incident details and corrective actions after resolution
Backups
Your data is backed up regularly to protect against data loss. Backups are tested to ensure they can be restored if needed.
Secure Product Development
Engineering Rigor
How We Update Our Products
New features and security improvements go through:
Isolated testing: Development and testing in non-production environments
Peer review: Thorough code review and security assessment
Phased rollout: Gradual rollout to catch issues early
Post-release monitoring: Active telemetry and monitoring after deployment
This process means updates can take time, but it reduces the risk of introducing new problems into your workflow.
Security Testing
We test our products for common vulnerabilities and issues:
Automated security testing: Integrated into development pipelines
Manual testing: Deep manual evaluations by our team
External perspectives: Independent evaluations on our security approach
Employee Access to Customer Data
Our employees can access customer data only when necessary to:
Provide technical support
Troubleshoot issues
Maintain the platform
Investigate security concerns
All access is logged and reviewed. Employees sign confidentiality agreements and receive security training.
Employee Awareness & Training
Human Defense
Our team understands that people are part of the security equation. We:
Security & Hygiene Training
Train employees on data handling, password hygiene, and phishing awareness.
Confidentiality Policies
Maintain clear policies on confidentiality and comprehensive data protection.
Regular Awareness Sessions
Conduct regular security awareness sessions and scenario reviews.
Screening & Background Checks
Screen employees and maintain rigorous background checks prior to onboarding.
Customer Responsibilities
Shared Responsibility
Security is a shared responsibility. To keep your hiring data safe, you should:
Account Management
Use strong, unique passwords for your AblyWorks account
Enable multi-factor authentication if available
Keep login credentials private and never share account access
Data Hygiene
Only upload or store candidate data that's necessary for hiring
Review and delete outdated candidate records
Don't store sensitive data (like SSNs) in places where it's not needed
Access Control
Grant team members only the permissions they need
Remove access for employees who no longer need it
Periodically review who has access to your account
Compliance
Ensure you have the right to collect and store candidate data
Comply with local data protection laws in your jurisdiction
Have a clear privacy policy for candidates
Responsible Disclosure
Security Researchers
If you discover a security vulnerability in AblyWorks, please report it responsibly.
Do Not:
Publicly disclose the vulnerability before we have time to fix it
Access or change data that isn't yours
Use the vulnerability to gain unauthorized access
Instead:
Email security@ablyworks.com with details of the vulnerability
Include steps to reproduce the issue if possible
Allow us reasonable time to investigate and respond
We appreciate responsible disclosure and will work with you to fix the issue quickly. We'll acknowledge your report and keep you updated on our progress.
Frequently Asked Questions
Q&A
Find answers to common questions about AblyWorks data security, privacy standards, and operational safeguards.
We use encryption for data in transit and at rest, limit who can access it, monitor for unauthorized access, and keep our systems updated. We also have processes to quickly identify and respond to security issues.
Your AblyWorks team members can access data based on the permissions you assign to them. Our employees can access your data only to provide support, maintain the platform, or investigate security issues, all access is logged and reviewed.
Passwords are never stored in plain text. They're hashed using secure algorithms, which means even our team can't see your password. If you forget your password, you can reset it through AblyWorks.
Yes. AblyWorks allows you to set roles and permissions for team members. You can grant access to specific features and candidate data based on each person's job function.
When we discover security issues, our team prioritizes fixes based on severity. Updates are tested thoroughly before being deployed to production. Critical issues are addressed quickly; less urgent issues are included in regular updates.
We use TLS 1.2 or higher for data in transit and industry-standard encryption for sensitive data at rest. We maintain current encryption standards and update them as security best practices evolve.
Email security@ablyworks.com with details of your concern. We'll investigate and respond to you as soon as possible.
Our security team assesses the vulnerability and its impact. If it affects customer data, we develop and test a fix, deploy it to production, and notify affected customers if necessary.
We use automated testing and manual review to assess our platform for vulnerabilities. We also receive security feedback from customers and third-party perspectives on our security approach.
Yes. You can export candidate data and other information from your AblyWorks account. Contact our support team for help with bulk exports or data migration.
Change your password immediately. Enable multi-factor authentication if you haven't already. Contact our support team to report the issue so we can investigate.
If we discover that customer data has been accessed without authorization, we investigate immediately. We notify affected customers and work to understand what happened and how to prevent it in the future.
Let's Talk Security
Direct Inquiry
Have questions about how AblyWorks keeps your data safe? Our security team is here to help.
Security Inquiries
Send your security assessments, compliance questions, or technical queries: