MoonTrack™ ATS Trust Center
We run a continuous security, privacy, and compliance program built for recruiting teams handling sensitive candidate and hiring data.
Uptime target
99.9% (90-day SLO)
Last penetration test
Scheduled Q3 2026
Data residency
EU + Africa regions
Compliance & certifications
SOC 2 Type I
In progress — target Q2 2027
GDPR
Compliant
NDPR (Nigeria)
Compliant
ISO 27001
Roadmap 2027
HIBP password screening
Active
AES-256 encryption
Active
Controls
Security Program
Documented governance, least-privilege access, quarterly access reviews, and an on-call rotation.
Data Protection
TLS 1.2+ in transit, AES-256 at rest, per-tenant row-level security, and managed daily backups.
Application Security
CSP, HSTS, MFA (TOTP), HIBP-screened passwords, magic-byte file scanning, and rate limiting.
Infrastructure
Supabase managed Postgres, Vercel edge hosting, secrets in vault, and infrastructure-as-code.
Security features in production
Multi-factor authentication
TOTP with AES-256-GCM server-side secret protection
Tenant isolation
Row-level security on every multi-tenant table
Audit logging
365-day retention with server-side PII redaction
IP allow-listing
Per-tenant request filtering via edge validation
Edge function JWT enforcement
Gateway-level auth on 45 of 62 functions
Rate limiting
Hourly quotas on AI assistant, CV parsing, and auth
File upload protection
Magic-byte verification and malicious content scanning
Signed URLs
Private storage buckets with short-lived signed access
Strict CSP + HSTS
Aligned meta and Nginx headers, no inline scripts
Encrypted credentials
Supabase Vault for provider API keys and secrets
Subprocessors
Third parties that may process customer data. We notify customers of material changes.
| Vendor | Purpose | Data processed | Location | DPA |
|---|---|---|---|---|
| Supabase | Database, auth, storage, edge functions | All customer and candidate data | EU / US | View |
| Resend | Transactional email delivery | Recipient email, message contents | US | View |
| Paystack | Subscription billing and payments | Billing contact, payment metadata | Nigeria | View |
| Google (Gemini API) | AI ranking, CV parsing, assistant | Job descriptions, CV text (no PII retained) | US / Global | View |
| Lovable AI Gateway | AI inference routing and fallback | Prompt and response payloads | EU / US | View |
| VerifyMe Nigeria | Background checks and identity verification | Candidate identity documents (with consent) | Nigeria | View |
| Vercel | Frontend hosting and CDN | Request metadata, no application data | Global edge | View |
Supabase
DPADatabase, auth, storage, edge functions
Data
All customer and candidate data
Location
EU / US
Google (Gemini API)
DPAAI ranking, CV parsing, assistant
Data
Job descriptions, CV text (no PII retained)
Location
US / Global
Lovable AI Gateway
DPAAI inference routing and fallback
Data
Prompt and response payloads
Location
EU / US
VerifyMe Nigeria
DPABackground checks and identity verification
Data
Candidate identity documents (with consent)
Location
Nigeria
Responsible disclosure
We welcome reports from the security community.
Report vulnerabilities to security@moontrackhr.com. We acknowledge reports within 2 business days, validate within 5, and aim to remediate critical issues within 30 days.
- Safe-harbor for good-faith research that respects user privacy and avoids service disruption.
- No public disclosure for 90 days or until a fix ships — whichever comes first.
- Researchers who report valid issues are credited in our hall of fame on request.
Documents and requests
Self-serve
Publicly available, no NDA required.
On request (NDA)
Available to prospects and customers under NDA.
• SOC 2 readiness letter
• Penetration test summary
• Security questionnaires (SIG Lite, CAIQ)
• Data Processing Addendum
• Architecture overview
Contact
We respond within 2 business days.
Security: security@moontrackhr.com
Privacy: privacy@moontrackhr.com
Legal: legal@moontrackhr.com
Support: support@moontrackhr.com