Candidate data deserves serious handling — by default
Complete per-company isolation, end-to-end encryption and LGPD built into the product: consent, configurable retention and automatic deletion.
- Native LGPD
- AES-256 at rest
- TLS 1.3 in transit
- Per-company isolation
- RBAC
- Audit of critical actions
LGPD built in, not bolted on
Consent, retention and deletion aren't a separate module — they're part of the application flow.
Explicit consent
User consent management at the moment of application, with clear legal basis and purpose.
Configurable retention
Data retention and deletion policies defined by your company, for each type of candidate information.
Automatic deletion
At the end of the defined period, candidate data is deleted automatically — with no reliance on a manual routine.
Data subject rights
Full support for data subject rights, in full compliance with Brazil's LGPD (Law 13.709/2018).
Every company isolated, every record encrypted
One company's data never mixes with another's, and it travels and rests encrypted.
Multi-tenant isolation
Complete data isolation between companies (multi-tenancy): one company's data never mixes with another's.
Encryption at rest
AES-256 encryption for data at rest.
Encryption in transit
TLS 1.3 for all communications (HTTPS), with SSL/TLS certificates automatically renewed.
Passwords and keys
Passwords hashed with secure algorithms (bcrypt) and secure cryptographic key management.
Only those who should, see what they should
Access with no password to remember, role-based permissions and an audit trail on critical actions.
Passwordless authentication
Magic Link authentication (no passwords to remember) and session tokens with automatic expiration.
Role-based access control
Role-based access control (RBAC): each role sees and does only what it should.
Audit of critical actions
Audit logging of all critical actions.
Brute force protection
Protection against brute force attempts on access.
Resilient, monitored infrastructure with backups
Hosting on providers with recognized certifications, continuous monitoring and tested recovery.
Certified providers
Hosting on certified providers (SOC 2, ISO 27001).
High availability
Geographic redundancy for high availability.
24/7 monitoring
24/7 infrastructure and application monitoring.
Daily backups
Automatic daily backups with 30-day retention and a disaster recovery plan tested regularly.
DDoS protection
Firewalls and DDoS protection.
Frequently asked questions
The most common questions from teams evaluating security and compliance.
Documents and policies
This commercial page summarizes the selling points; the documents below carry the full policy.
Security that clears your legal team's bar
Bring your IT and compliance team. We'll show how isolation, encryption and built-in LGPD work in practice.