Security / Compliance

Data compliance starts with the backend boundary.

Talent Intelligence Lab ATS is deployed on Supabase-backed infrastructure and designed around private hiring records, workspace access, and a clear shared-responsibility model.

Supabase trust layer

Certifications and controls from the managed backend.

01

SOC 2 Type 2

Supabase states that its hosted platform is SOC 2 Type 2 compliant and assessed annually for security, availability, confidentiality, processing integrity, and privacy controls.

View Supabase reference
02

ISO/IEC 27001:2022

Supabase announced ISO/IEC 27001:2022 certification for its information security management system across Database, Auth, Storage, Realtime, Edge Functions, and the Data API.

View Supabase reference
03

HIPAA pathway

For PHI/ePHI workflows, Supabase documents a HIPAA path that requires a signed BAA and the HIPAA add-on. The ATS does not assume HIPAA scope by default.

View Supabase reference
04

Product security controls

Supabase documents product-level hardening across Auth, Database, Storage, Realtime, API exposure, secrets, roles, RLS, and related controls.

View Supabase reference

Shared responsibility

Supabase certification supports the ATS. It does not certify the whole app by itself.

This distinction matters for employers and agencies handling candidate data. Supabase provides audited platform controls; the ATS and each customer still need appropriate process, access, retention, and legal controls around the data.

Supabase boundary

Supabase certifications cover controls operated by Supabase inside the hosted platform and its documented compliance boundary.

ATS boundary

Talent Intelligence Lab is responsible for how the ATS is configured, what data is collected, who gets access, and how records are retained.

Customer boundary

Employers and agencies remain responsible for their own hiring policies, applicant notices, consent, retention rules, and legal obligations.

Residency decisions

Supabase projects are created in a selected region. Region selection and any jurisdiction-specific requirements should be confirmed during onboarding.

ATS data controls

Candidate data is handled as controlled workspace data.

01

Authenticated workspace

ATS access is built around Supabase Auth, invite-led setup, organization membership, and private application routes.

02

Tenant-aware data model

Candidate records, jobs, files, notes, scorecards, and offers are scoped to the correct workspace and role boundaries.

03

Least-privilege access

Public careers intake is separated from internal recruiter, hiring-manager, agency, admin, and platform-owner workflows.

04

Candidate evidence trail

Hiring decisions stay attached to the record so review context is not scattered across spreadsheets, inboxes, and local files.

Data lifecycle

Collection, storage, access, and review are separated intentionally.

01

Collect

Public applications collect candidate information through a separate careers/apply surface.

02

Store

Candidate data is stored as workspace records backed by Supabase Postgres and related product controls.

03

Control

Access is shaped through authentication, roles, membership, RLS-oriented architecture, and private routes.

04

Review

Files, feedback, AI assistance, offers, and activity are kept near the candidate record for accountable review.

Compliance review

Currently invite only.

Compliance questions can be reviewed during onboarding, including Supabase trust documentation, region selection, candidate data handling, retention expectations, access boundaries, and PHI/ePHI exclusions.