EAST COAST HIRE

Security

How East Coast Hire protects your organization's data.

A truthful account of implemented controls — not a certification claim.

Encryption

Data is encrypted in transit (TLS) and at rest through our infrastructure provider. OAuth integration credentials are additionally encrypted at the application layer before storage.

Access control

Every record is scoped to your organization and enforced by database-level row-level security, not just application checks. Role-based permissions govern what each member can see and do.

Organization isolation

No organization can query, export, or otherwise access another organization's data. This is enforced at the database policy level.

Approval-driven external actions

East Coast Hire never sends an email, creates a calendar event, or takes another external action without explicit human approval.

Audit history

Organization activity, security events, and administrator actions are recorded for review.

Secure integrations

Connected services use OAuth2 with PKCE where supported; credentials are never exposed to the browser.

Monitoring

Health checks and structured error logging support operational visibility. See our status page for current platform status.

Responsible disclosure: if you believe you've found a security vulnerability, contact security@eastcoasthire.com (placeholder) with details. Please do not access, modify, or exfiltrate data belonging to other organizations while investigating. We aim to acknowledge reports within a reasonable timeframe.

East Coast Hire does not currently claim SOC 2, ISO 27001, HIPAA, or other formal certifications. This page will be updated if and when such reviews are completed.