Trust · Security · Compliance
Trust at Curriculo
Your hiring data — candidates, pipelines, offers — is some of the most sensitive information your team handles. This page explains, in plain language, how Curriculo hosts, protects, and handles it: what we do, and where to reach us when you need more.
01 · Infrastructure
Where your data lives
Curriculo runs on managed cloud infrastructure operated under AWS security baselines, so the physical and network layers are inherited from a provider whose entire business is protecting them.
Hosting
US-hosted on AWS, with strict tenant isolation.
All Curriculo production data is stored in the United States on Amazon Web Services. Every customer workspace is a separate tenant, logically isolated from every other.
Tenant isolation
Your workspace is yours alone
Data belonging to one hiring team is never visible to another. Isolation is enforced at the application layer for every request, not just at login.
Managed infrastructure
Hardened by default
We rely on AWS-managed services with security patching and hardware lifecycle handled by the platform, and keep our own surface area small on purpose.
02 · Security practices
Protected by default
These protections apply to every Curriculo workspace from day one. You should not have to configure your way to safety.
Encryption
Encryption in transit and at rest
Data moving between you and Curriculo is encrypted in transit, and data stored by Curriculo is encrypted at rest.
Access control
Least-privilege access
Access to production systems follows the principle of least privilege and is granted only to the team members and purposes that need it.
Monitoring
Logged and reviewed
Security-relevant events are logged so that unusual activity can be investigated rather than discovered after the fact.
Secure development
Reviewed before release
Changes to Curriculo go through code review before they ship, and security impact is considered part of every change.
Backups
Recoverable by design
Customer data is backed up so that an infrastructure failure is an inconvenience, not a loss of your hiring history.
Vendors
Vetted subprocessors
We keep track of every third-party vendor and subprocessor that touches the service, and expect the same security posture from them that we hold ourselves to.
03 · Compliance
Independently assessed
Curriculo's application security is assessed under an industry-recognized framework for cloud application security, aligned with modern AppSec standards.
Certification
ADA CASA AL1 (Legacy CASA Tier 2)
Curriculo has completed assessment under ADA CASA AL1 (Legacy CASA Tier 2), the application-security assessment framework recognized by major cloud marketplaces.
What it means for you
An external party has looked at the locks
- Curriculo's application security controls were assessed by an independent reviewer against an established AppSec framework.
- The assessment covers how we build, run, and protect the application — not just a checklist we filled in ourselves.
- Need documentation for your own review? Ask us — we share security details with customers and evaluators under NDA.
04 · Data handling & privacy
Your data, treated like it's ours
Hiring data is people data. Here is how Curriculo thinks about collecting, using, and removing it.
Collection
Only what the product needs
We collect the data Curriculo needs to screen, score, and manage candidates — and we do not build shadow profiles beyond that.
Use
Used to serve you, not sold
Your workspace data is used to provide Curriculo to your team. We do not sell candidate or customer data, and we do not share it for advertisers' benefit.
Deletion
Removal when you ask
Ask us to remove your account or workspace data and we will process the deletion. Candidates can also request removal of their own information.
AI features
AI in service of your hiring
AI features in Curriculo — screening, scoring, search — exist to serve your workspace. Questions about how AI touches your data are welcome at any time.
Policy
The full legal version
The complete detail lives in our privacy policy and terms of use.
05 · Responsible disclosure
Found something? Tell us first.
If you believe you have found a security vulnerability in Curriculo, report it to our security team directly. Reports go to the people who can act on them. Please give us reasonable time to remediate before public disclosure, and avoid testing on live candidate data.