Back to Home

MoonTrack™ ATS Trust Center

We run a continuous security, privacy, and compliance program built for recruiting teams handling sensitive candidate and hiring data.

Uptime target

99.9% (90-day SLO)

Last penetration test

Scheduled Q3 2026

Data residency

EU + Africa regions

Compliance & certifications

SOC 2 Type I

In progress — target Q2 2027

GDPR

Compliant

NDPR (Nigeria)

Compliant

ISO 27001

Roadmap 2027

HIBP password screening

Active

AES-256 encryption

Active

Controls

Active

Security Program

Documented governance, least-privilege access, quarterly access reviews, and an on-call rotation.

Active

Data Protection

TLS 1.2+ in transit, AES-256 at rest, per-tenant row-level security, and managed daily backups.

Active

Application Security

CSP, HSTS, MFA (TOTP), HIBP-screened passwords, magic-byte file scanning, and rate limiting.

Active

Infrastructure

Supabase managed Postgres, Vercel edge hosting, secrets in vault, and infrastructure-as-code.

Security features in production

  • Multi-factor authentication

    TOTP with AES-256-GCM server-side secret protection

  • Tenant isolation

    Row-level security on every multi-tenant table

  • Audit logging

    365-day retention with server-side PII redaction

  • IP allow-listing

    Per-tenant request filtering via edge validation

  • Edge function JWT enforcement

    Gateway-level auth on 45 of 62 functions

  • Rate limiting

    Hourly quotas on AI assistant, CV parsing, and auth

  • File upload protection

    Magic-byte verification and malicious content scanning

  • Signed URLs

    Private storage buckets with short-lived signed access

  • Strict CSP + HSTS

    Aligned meta and Nginx headers, no inline scripts

  • Encrypted credentials

    Supabase Vault for provider API keys and secrets

Subprocessors

Third parties that may process customer data. We notify customers of material changes.

Subscribe to updates

Supabase

DPA

Database, auth, storage, edge functions

Data

All customer and candidate data

Location

EU / US

Resend

DPA

Transactional email delivery

Data

Recipient email, message contents

Location

US

Paystack

DPA

Subscription billing and payments

Data

Billing contact, payment metadata

Location

Nigeria

Google (Gemini API)

DPA

AI ranking, CV parsing, assistant

Data

Job descriptions, CV text (no PII retained)

Location

US / Global

Lovable AI Gateway

DPA

AI inference routing and fallback

Data

Prompt and response payloads

Location

EU / US

VerifyMe Nigeria

DPA

Background checks and identity verification

Data

Candidate identity documents (with consent)

Location

Nigeria

Vercel

DPA

Frontend hosting and CDN

Data

Request metadata, no application data

Location

Global edge

Responsible disclosure

We welcome reports from the security community.

Report vulnerabilities to security@moontrackhr.com. We acknowledge reports within 2 business days, validate within 5, and aim to remediate critical issues within 30 days.

  • Safe-harbor for good-faith research that respects user privacy and avoids service disruption.
  • No public disclosure for 90 days or until a fix ships — whichever comes first.
  • Researchers who report valid issues are credited in our hall of fame on request.

Documents and requests

Self-serve

Publicly available, no NDA required.

On request (NDA)

Available to prospects and customers under NDA.

• SOC 2 readiness letter

• Penetration test summary

• Security questionnaires (SIG Lite, CAIQ)

• Data Processing Addendum

• Architecture overview

Contact

We respond within 2 business days.

We use cookies to improve your experience. Essential cookies are always active. You can accept or reject non-essential cookies used for error monitoring and analytics. Learn more