SOC 2 Type 2
Supabase states that its hosted platform is SOC 2 Type 2 compliant and assessed annually for security, availability, confidentiality, processing integrity, and privacy controls.
View Supabase referenceSecurity / Compliance
Talent Intelligence Lab ATS is deployed on Supabase-backed infrastructure and designed around private hiring records, workspace access, and a clear shared-responsibility model.
Supabase trust layer
Supabase states that its hosted platform is SOC 2 Type 2 compliant and assessed annually for security, availability, confidentiality, processing integrity, and privacy controls.
View Supabase referenceSupabase announced ISO/IEC 27001:2022 certification for its information security management system across Database, Auth, Storage, Realtime, Edge Functions, and the Data API.
View Supabase referenceFor PHI/ePHI workflows, Supabase documents a HIPAA path that requires a signed BAA and the HIPAA add-on. The ATS does not assume HIPAA scope by default.
View Supabase referenceSupabase documents product-level hardening across Auth, Database, Storage, Realtime, API exposure, secrets, roles, RLS, and related controls.
View Supabase referenceShared responsibility
This distinction matters for employers and agencies handling candidate data. Supabase provides audited platform controls; the ATS and each customer still need appropriate process, access, retention, and legal controls around the data.
Supabase certifications cover controls operated by Supabase inside the hosted platform and its documented compliance boundary.
Talent Intelligence Lab is responsible for how the ATS is configured, what data is collected, who gets access, and how records are retained.
Employers and agencies remain responsible for their own hiring policies, applicant notices, consent, retention rules, and legal obligations.
Supabase projects are created in a selected region. Region selection and any jurisdiction-specific requirements should be confirmed during onboarding.
ATS data controls
ATS access is built around Supabase Auth, invite-led setup, organization membership, and private application routes.
Candidate records, jobs, files, notes, scorecards, and offers are scoped to the correct workspace and role boundaries.
Public careers intake is separated from internal recruiter, hiring-manager, agency, admin, and platform-owner workflows.
Hiring decisions stay attached to the record so review context is not scattered across spreadsheets, inboxes, and local files.
Data lifecycle
Public applications collect candidate information through a separate careers/apply surface.
Candidate data is stored as workspace records backed by Supabase Postgres and related product controls.
Access is shaped through authentication, roles, membership, RLS-oriented architecture, and private routes.
Files, feedback, AI assistance, offers, and activity are kept near the candidate record for accountable review.
Compliance review
Compliance questions can be reviewed during onboarding, including Supabase trust documentation, region selection, candidate data handling, retention expectations, access boundaries, and PHI/ePHI exclusions.