HireUp uses the Amazon AWS Aurora MySQL relational databases for application and user data storage. Amazon Aurora is fully managed by Amazon Relational Database Service (RDS), which automates time-consuming administration tasks like hardware provisioning, database setup, patching, and backups.
All of our Aurora database clusters use the industry standard AES-256 encryption algorithm to encrypt data on the server that hosts the DB clusters. Aurora handles authentication of access and decryption of data transparently with a minimal impact on performance.
Customer master keys used for encrypting and decrypting Amazon Aurora resources are controlled through the AWS Key Management Service, allowing us to control how these keys are being used. Our Key Management Service is linked to our AWS CloudTrail , allowing us to audit CMK usage to verify that CMKs are being used appropriately.
Our SSL certificate uses the SHA-256 bit hashing algorithm to encrypt and authenticate data in transit. All of our SSL certificates are digitally signed by the Sectigo Certificate Authority. All data transmitted is done through TLS.
All data transits go through our SSL-protected AWS Load Balancer which routes traffic to our servers, which are also protected by SSL.
Our application load balancer utilizes AWS Web Application Firewall (WAF) to enable web access control lists (Web ACL), which monitor HTTPS request to help protect our services from attacks
HireUp aims to collect as little data as possible, while being transparent with users on how their data is collected and stored. Users opt into HireUp’s privacy policy which outlines this information, as well as their Right to Access and Right to be Forgotten. HireUp adheres to GDPR when collecting and storing personal data.
The HireUp platform is hosted on Amazon AWS Servers which have SOC 2 Type II and ISO 27001 certifications, among others. The certified protections include dedicated security staff, strictly managed physical access control, and video surveillance
HireUp performs regular infrastructure vulnerability scans.
HireUp leverages 3rd party penetration testing firms annually to test the HireUp Platform Infrastructure.
HireUp underoges regular 3rd party security audits