Security & Privacy

Resumes are personal data. We treat them that way.

TalentGraph processes CVs, contact details and employment history — some of the most sensitive material a company handles about people who do not yet work there. This page sets out exactly what happens to a document you upload, where it is stored, who can reach it, and what we have not yet certified.

TLS 1.2+ in transit Encrypted at rest No training on customer data Self-hosting available SOC 2 Type II ISO 27001
Read the dashed badges literally.SOC 2 and ISO 27001 are on the roadmap and are not certified today. We would rather say so here than let a badge imply an audit that has not happened. Ask us for current status before a procurement review.

Last updated: 10 September 2026

What happens to a document you upload

An uploaded resume or job posting is read into memory and converted to text. That text is hashed and checked against the cache; on a hit, the stored structured result is returned and no further processing occurs. On a miss, the local rule engine extracts what it can. Only if local confidence is below threshold is a redacted extract sent to the configured model provider to fill the remaining fields.

The structured result — and, depending on your configuration, the extracted text — is stored so that the candidate becomes searchable in your talent pool. The original binary file is not retained unless you explicitly enable document storage.

Sub-processors and model providers

When the AI fallback triggers, text is sent to whichever provider you have configured: Google (Gemini), OpenAI, or Anthropic. Under those providers’ API terms, content sent through the paid API is not used to train their models. On Enterprise you can supply your own API keys, in which case the request is billed to and governed by your own account with that provider.

We do not use your documents, parsed records or match results to train any model of our own. There is no exception to this for “improving the product”: the local engine learns vocabulary such as skill names and section headings, not candidate data.

Encryption

  • In transit: all traffic to the API and the web app is TLS 1.2 or higher. Model provider calls are likewise made over TLS.
  • At rest: the datastore holding parsed records is encrypted at rest.
  • Secrets: model API keys are held as environment configuration, never in the database alongside candidate records, and are not logged.

Access control

Access to production systems is limited to the engineers who operate them, over authenticated sessions, and is reviewed when someone changes role or leaves. Support staff do not browse customer talent pools; if diagnosing an issue requires looking at a specific document, we ask you first.

Enterprise deployments support SSO and audit logging so that access within your own organisation is your policy to set and your log to read.

Data retention and deletion

  • Parsed candidate records persist until you delete them, or until your account is closed.
  • Deleting a candidate removes the structured record and its cache entry.
  • On account closure, customer data is deleted within 30 days. You can export everything as JSON before that.
  • Enterprise customers can set shorter retention windows, including automatic deletion of parsed records after a fixed period.

Self-hosting

TalentGraph ships as a container and can run entirely inside your own network or VPC. In that configuration resume files never reach our infrastructure at all, and the only outbound traffic is the AI fallback call to your chosen model provider — which you can point at your own account, or disable outright to run local-only.

Data subject rights

Candidates whose resumes you process have rights over that data under GDPR, India’s DPDP Act and comparable regimes — access, correction, erasure and objection among them. In that relationship you are the controller and TalentGraph is the processor: we act on your instruction, and the platform provides the export and deletion endpoints you need to honour a request. A Data Processing Agreement is available on request.

Reporting a vulnerability

If you believe you have found a security issue, please email the details to our security contact rather than filing a public issue. We will acknowledge receipt, keep you updated while we investigate, and credit you if you would like that. We will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service disruption.

Contact the security team →

What we have not done yet

We are not SOC 2 or ISO 27001 certified at the time of writing, and we do not currently run a paid bug bounty. Both are planned. If your procurement process requires a completed audit today, tell us early so we can be straight with you about timing rather than waste your evaluation cycle.

Security review coming up?

Send us your questionnaire. We would rather answer it directly than have you infer the answers from a marketing page.