Last updated: August 2026

Information Security Policy

Eximius handles hiring data on behalf of our customers, including candidate profiles, resumes, interview recordings, evaluation notes, and recruiter communications. This policy describes the controls we use to keep that information confidential, accurate, and available, and what we expect of everyone who works with it.

1. Purpose and Scope

This policy applies to all Eximius systems, applications, and infrastructure used to deliver the Eximius platform, and to all employees, contractors, and third parties who access those systems. It covers customer data, candidate data, employee data, and Eximius internal information in every form: production databases, backups, logs, documents, and communications.

2. Governance and Responsibility

Security is owned at the leadership level. Our engineering leadership is accountable for the design and operation of security controls, and every team member is responsible for following this policy in their day to day work. We review the policy at least annually, and sooner when our architecture, our vendors, or the regulatory landscape changes in a way that matters.

3. Data Classification and Handling

We classify information so that protection matches sensitivity:

Customer data is never used for purposes outside the delivery and improvement of the contracted service, and it is never sold.

4. Encryption

All traffic between users, our applications, and our infrastructure is encrypted in transit using TLS, with HTTPS enforced at the edge and certificates managed automatically so they do not lapse. Data at rest is encrypted by default across our managed database platform, using AES-256 with keys managed by the cloud provider. That protection is applied at the server level and extends to database files, transaction logs, replicas, and automated backups. Application secrets such as API keys and service tokens are held in a managed key vault and injected into running workloads at deploy time. Account passwords are never stored in readable form: they are salted and hashed with a modern password hashing function, either bcrypt or Argon2id depending on the system.

5. Access Control

Access to production systems follows the principle of least privilege. Specifically:

6. Infrastructure and Network Security

The Eximius platform runs on established cloud infrastructure providers that maintain their own physical and environmental security programs, including certified data centers. Our workloads sit behind managed firewalls and private networking, with public exposure limited to the endpoints that need it. We apply security patches to operating systems, runtimes, and dependencies on a regular cadence, and out of band when a high severity vulnerability is disclosed.

7. Secure Development

Security is part of how we build, not a step at the end. Changes reach production through pull requests that carry peer review, with automated test suites running against proposed changes before they are merged. Development, QA, and production run as separate environments with separate deployment pipelines, and production data is not copied into lower environments for testing.

8. Logging, Monitoring, and Audit Trails

Platform activity is logged, including authentication events, administrative actions, and changes to candidate records. Audit trails let customers see who did what and when, which matters both for hiring governance and for investigating anything unusual. Access to logs is restricted to authorized personnel, and logs are retained for a period appropriate to their purpose.

9. Artificial Intelligence and Model Use

Eximius uses commercial AI models to screen, score, and summarize. Most model traffic is routed through a managed model gateway, which we configure to exclude providers that train on submitted data, and the rest goes directly to enterprise providers under business terms. In every case we send only the data a given task requires. Automated evaluations are designed to be reviewable, with the reasoning recorded so a human can inspect and override a result. Our broader commitments on fairness and human oversight are set out in our Ethical AI Policy.

10. Vendor and Third Party Management

We review the security posture of vendors who process customer or candidate data before onboarding them, and we limit what each vendor can access to what their service actually requires. Data processing agreements are put in place where the vendor handles personal data on our behalf. Vendor relationships are reviewed periodically, and access is removed when a vendor is no longer in use.

11. Incident Response

We maintain an incident response process covering detection, triage, containment, eradication, recovery, and post incident review. If we confirm a security incident that affects customer or candidate personal data, we will notify affected customers without undue delay, describe what we know, and share the steps we are taking. Every significant incident is followed by a written review that identifies the root cause and the corrective actions.

12. Business Continuity and Backups

Production data is backed up on a regular schedule, and backups inherit the encryption applied to our stored data. Our infrastructure runs on an orchestrated platform that replaces failed application instances automatically, and we maintain recovery plans for the scenarios most likely to interrupt service.

13. Data Retention and Deletion

We retain customer and candidate data for as long as it is needed to deliver the service and to meet legal, contractual, and record keeping obligations. Our platform lets organizations share jobs and candidates with each other where both sides explicitly agree to it, which means a single hiring record can form part of more than one organization's history. Removing that record for one party would leave the others with an incomplete and inaccurate account of decisions they took, so we do not selectively delete historical transactional data.

When a customer agreement ends, we disable access rather than erase records. The organization and its users can no longer reach the platform or the data through it, and the underlying records are retained under the terms of that agreement. Customers can request an export of their data at any time. If you are a candidate and want to know what we hold about you or ask us to limit how it is used, write to us at [email protected] and we will tell you what we can act on and what we are obliged to keep. See our Privacy Policy for how we handle personal information more generally.

This is our current practice, and we are working to improve it. As part of our GDPR compliance program we are building the ability to separate the records that must be preserved for regulatory, contractual, and shared history reasons from those that do not, so that data outside that set can be deleted when an agreement ends. We will describe the change here once it is in place rather than in advance of it.

14. Personnel Security and Awareness

Employees and contractors are bound by confidentiality obligations and receive security awareness guidance covering phishing, credential hygiene, device security, and safe handling of candidate data. Access is provisioned on joining and revoked on departure as part of the offboarding process. Company devices are expected to run current operating systems with disk encryption and screen lock enabled.

15. Compliance

Our controls are designed to align with recognized frameworks including SOC 2 and ISO 27001, and with data protection regulations such as GDPR and CCPA where they apply to the data we process. Our formal SOC 2 audit is in progress, and our GDPR compliance program is being formalized alongside it. GDPR has no certification to obtain, so we describe that work as compliance rather than certification. We do not claim certifications we have not completed, and we are happy to share current status and available documentation with customers under NDA.

16. Reporting a Security Concern

If you believe you have found a vulnerability in the Eximius platform, or you have a question about this policy, contact us at [email protected]. Please include enough detail to reproduce the issue. We investigate every report we receive, and we ask that you give us a reasonable window to remediate before disclosing anything publicly. We will not pursue action against researchers who report in good faith and avoid privacy violations, service disruption, or data destruction while testing.

General contact

For anything else, including compliance documentation requests, write to [email protected].

17. Changes to This Policy

We may update this policy as our platform and controls evolve. Material changes will be reflected here with a revised date at the top of the page. Continued use of the Eximius platform after an update means you accept the current version.