Security
We treat candidate and employer data as the most sensitive material we hold. This page summarises the technical and organisational controls we operate.
Infrastructure
Production workloads run on Amazon Web Services in the US East (N. Virginia) region. Static assets and marketing sites are served through AWS Amplify and CloudFront. Application databases are Amazon-managed services with automated backups and point-in-time recovery. We do not operate self-hosted servers.
Encryption
All traffic between users and our services is encrypted with TLS 1.2 or above. Data at rest — including candidate profiles, assessment responses, and file uploads — is encrypted using AES-256 with keys managed by AWS Key Management Service.
Access control
Staff access to production systems is restricted to a small named group, enforced through single sign-on with mandatory multi-factor authentication. Access is granted on a least-privilege basis, reviewed quarterly, and logged. No production credentials are shared or embedded in code.
Application security
We follow secure-development practices including code review, dependency scanning, and static analysis on every change. Vulnerabilities in third-party dependencies are triaged and patched on a schedule that reflects their severity.
Data handling
Candidate data are used only for the purposes described in our Privacy Policy: matching candidates to opportunities, and providing employers with evaluation results for specific roles. Data are retained for the periods stated there, and deleted or anonymised at the end of the retention window.
Responsible disclosure
If you believe you have found a security issue in any iVerse or EVA property, please email security@evaandcompany.com with a description and reproduction steps. We commit to acknowledging your report within two business days and to keeping you informed as we work on a fix. Machine-readable contact information is published at /.well-known/security.txt.