SECURITY & TRUST

Your workforce data, handled with restraint.

JobRoute Companies analyzes cohorts, not individuals: records are de-identified before storage, and we keep only what the analysis needs.

DATA WE HOLD

De-identified by default.

Employee identifiers are de-identified before they are stored

IDs are hashed with HMAC-SHA256 (server-side key, tenant-namespaced) before storage; the raw ID is never persisted. Manager references are hashed too, preserving the org chart.

We do not store names, emails, or other personal details

The roster record is minimal: ID hash, role title, department, tenure, seniority band, location. No column exists for a name, email, date of birth, or compensation.

Personal data is stripped from every API response

The insights and cohort endpoints return only anonymized, role-level fields; no identifier hash or raw record ever leaves the API. Analysis runs on cohorts, not identifiable people.

Connector credentials are used once and never stored

Workday and SuccessFactors credentials are used in-memory for that single ingestion, then discarded. There is no credential table; we hold no standing copy of your HRIS secrets.

HOW IT RUNS

Hardened infrastructure.

Connectors are guarded against server-side request forgery

Outbound requests block private, loopback, link-local, and cloud-metadata ranges, re-check hosts to defeat DNS rebinding, and never follow redirects.

Encryption in transit and at rest

All traffic is HTTPS, enforced for connector URLs in production. Data at rest lives in managed Azure Database for PostgreSQL, encrypted by default with Microsoft-managed keys.

Strict per-tenant isolation

Every query is scoped to your tenant; one company can never read another’s data. Sign-in is passwordless: a single-use magic link issues a signed, httpOnly, secure session cookie.

Hosting

JobRoute Companies runs on Microsoft Azure in the United States: Azure Container Apps for the API, Azure Database for PostgreSQL for the data. We will confirm the region in writing for your review.

OWNERSHIP

Your data, your terms.

You control the data, and it is yours to remove

Deleting your tenant cascades to every related record: employees, snapshots, scores, and role mappings. Exports and earlier deletions are handled on request.

Grounded in public data, not a black box

Scores are deterministic over public sources (Anthropic Economic Index, O*NET, BLS, WEF) applied to your anonymized roles. Same input, same result; every figure is cited on the Methodology page.

IN PROGRESS

What we have not done yet.

Stated plainly rather than implied. As of today:

  • A formal SOC 2 examination. We are not yet certified and do not claim to be. We can share our security practices in detail under NDA in the meantime.
  • Self-service data export and deletion in the product UI. Today these are handled on request through support.
  • Server-side session revocation. Sessions currently expire on a fixed schedule rather than being individually revocable.

Questions from your security team?

We are glad to walk through any of this in detail, share documentation under NDA, or confirm specifics in writing for your review.

hello@jobroute.ai