How MoonTrack protects your candidate data
MoonTrack™ is an applicant tracking system operated by S&A Partners. This page is written for the person who has to approve us internally: what is in place today, what is not, and who else touches your data.
Last reviewed: February 2026
Controls in place today
Tenancy isolation
Every customer organisation is a separate tenant. Isolation is enforced in the database itself with row-level security on candidate, application, job, message and document tables — not in application code that a bug could bypass. Automated cross-tenant tests run on every deployment and fail the release if one tenant can read another tenant’s rows.
Encryption
All traffic between your browser and MoonTrack uses TLS 1.2 or higher. Data at rest, including database storage, file uploads and backups, is encrypted with AES-256 by our infrastructure provider. Third-party integration credentials are stored encrypted and are never returned to the browser.
Access control and authentication
Role-based access control separates platform owners, organisation admins, hiring team members and candidates. Multi-factor authentication is available to all accounts and can be required for an organisation. Passwords are hashed, checked against known-breached password lists, and sessions expire automatically.
Audit logging
Administrative actions, permission changes, candidate CV downloads and data exports are written to an append-only audit log with actor, timestamp and organisation. Logs are scrubbed of personal data such as email addresses, phone numbers and tokens before storage.
Backups and recovery
The production database is backed up continuously with point-in-time recovery. Recovery procedures are documented in our business continuity plan and rehearsed against a restore target of 24 hours.
Personnel and least privilege
Production access is limited to named administrators, requires multi-factor authentication, and is logged. Support staff cannot read candidate records outside a customer-authorised support session.
Nigeria Data Protection Act 2023
For Nigerian customers, you are the data controller for candidate data you process in MoonTrack and we act as your data processor. We process personal data only on your documented instructions, assist with data subject requests, and notify you without undue delay if we become aware of a personal data breach affecting your organisation.
A Data Processing Agreement covering these terms is available on request and can be signed before onboarding. Where a customer is subject to GDPR or CCPA, the same agreement covers those obligations.
We do not sell personal data, and we do not use your candidate data to train AI models. AI screening sends only the candidate material required for the evaluation you requested, and the provider does not retain it for training.
Data residency
Production data is stored in our managed cloud infrastructure with backups held in the same region. AI screening requests are processed by our AI provider and may transit outside your country of operation for the duration of the request. We will confirm the current storage region in writing for any customer that needs it for their own compliance record, and we can discuss region requirements before onboarding.
Retention and deletion
| Data | Retention |
|---|---|
| Candidate and application records | Retained for the life of your account, then deleted within 30 days of termination unless you ask us to delete sooner. |
| Uploaded CVs and documents | Same as candidate records. Deleting a candidate removes the stored file. |
| Operational logs | 90 days. |
| Audit logs | 365 days. |
| Backups | Rolling window; deleted data ages out of backups within 30 days. |
You can export your organisation’s data at any time from the dashboard, and you can request full deletion by emailing us. Your data belongs to you.
Sub-processors
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, file storage, serverless functions |
| Google (Gemini via Lovable AI Gateway) | AI screening and CV parsing |
| Resend | Transactional email delivery |
| Paystack, Flutterwave | Payment processing |
We publish material changes to this list. The live list is also available in the Trust Center.
What we do not yet have
Stated plainly so you are not surprised later in your review.
- SOC 2 Type IIRoadmap — controls implemented, no independent audit completed. We do not claim certification.
- ISO 27001Roadmap — not currently certified.
- Independent penetration testRoadmap — internal and automated security testing only at present.
- Customer-configurable retention windowsRoadmap — retention is currently set by the schedule above.
Security contact
Vulnerability reports, security questionnaires and DPA requests: security@moontrackhr.com
We acknowledge reports within two business days and will keep you updated until the issue is resolved. We do not pursue legal action against good-faith researchers.
