Security
Governance first.
Built into every layer.
Access, monitoring, audit and data isolation — the controls below are verified against the product source.
01 / 04
Access
- Two-factor sign-in
- A one-time code on sign-in, enabled by default for every account.
- Password storage
- Passwords stored as bcrypt hashes and compared in constant time.
- Sessions & idle lock
- Sessions expire; idle workstations lock under a policy you set.
- Invitations
- Accounts are created from invitations with a token that expires.
02 / 04
Permissions
- Roles as data
- Module → feature → action. A new module needs no code.
- Portal access control
- Lock, restrict or open the portal per group and per time window.
- Masked fields
- Reading sensitive fields needs the permission, per field.
- Membership scoping
- Projects, teams and rooms decide what a person sees.
03 / 04
Audit
- Immutable trail
- Every significant change with actor, target and time; it cannot be edited.
- Policy acceptance
- Rules accepted per person with a timestamp; a changed rule asks again.
- Corrections as requests
- Time, attendance and document corrections keep the original.
- AI under review
- Every AI recommendation visible for human review.
04 / 04
Platform
- Tenant isolation
- Every record carries its organization; queries are scoped at the data layer.
- API hygiene
- Rate limiting, input sanitization and request tracking on every API route.
- System health
- Service status and checks visible to admins and talents.
- Deployment status
- Which version is running where.
What we do not claim
Talent Portal does not claim certifications it does not hold. If your organization needs a security questionnaire answered, ask for it in the pilot conversation.
Roles & accessThe pilot
Don't replace your stack on day one.
Start with the one workflow where fragmentation costs the most. Run Talent Portal alongside your current tools, measure the result, and expand only if it works.

