Security and trust

Security your team can verify.

EEA hosting, layered access, encrypted data, monitored activity, tested recovery, and contractual accountability around Hire, Onboard, and Grow.

  • EEA processing
  • TLS 1.2+ and AES-256
  • DPA and audit rights

The core controls are not a sales footnote.

They are part of how CapoFine hosts, protects, monitors, and recovers the customer data entrusted to Hire, Onboard, and Grow.

EEA infrastructure

Frankfurt and Amsterdam

Core database and file storage run in Frankfurt. Application hosting and backup replication run in Amsterdam.

Encryption

Protected in transit and at rest

Traffic uses TLS 1.2 or higher. Stored data and backups use AES-256 encryption, with additional protection for uploaded files.

Access control

Least privilege by design

Role-based permissions, secure sessions, SSO-based MFA, one-time magic links, and restricted production access limit who can reach data.

Continuity

Encrypted, tested backups

Daily full and continuous incremental backups are encrypted, geographically replicated, retained for at least 30 days, and recovery-tested.

CapoFine protects the service.

We operate the platform, restrict production access, monitor activity, maintain recovery procedures, and support customers with privacy and incident obligations.

  • Encrypt data and backups
  • Monitor and investigate security events
  • Maintain subprocessors and recovery controls

Your organisation controls its data.

You determine the lawful purpose, authorised users, content, permissions, retention choices, and the people responsible for candidate and employee decisions.

  • Keep administrators and access rights current
  • Provide notices and lawful instructions
  • Report concerns and manage data-subject requests

One security model. Exact commitments in writing.

The standard control baseline is public. Package-specific uptime, support, recovery, retention, and implementation terms remain in the signed agreement.

EEA data location

Standard platform processing stays in the EEA, with core services in Frankfurt and Amsterdam.

Standard

Identity and permissions

Granular role-based access, secure sessions, SSO options, MFA through identity providers, and production-access restrictions.

Configured

Retention and recovery

30-day deletion after termination is standard. Longer migration windows, backup retention, RTO, and RPO vary by agreement.

Contract

Audit and assurance

Customers receive documented audit rights. CapoFine currently follows recognised security practices but does not claim ISO 27001 or SOC 2 certification.

Documented

Incident handling

A defined response plan covers detection, containment, investigation, recovery, and notice without undue delay, where possible within 24 hours.

DPA backed

Subprocessors

DigitalOcean, MongoDB Atlas, AWS, and optional APIDeck services support the standard platform under written data-protection terms.

Published

Procurement questions, answered plainly.

The baseline is public. The signed agreement identifies the package-specific commitment that applies to your organisation.

Where is CapoFine data hosted?

The standard platform processing described in our Data Processing Agreement takes place in the EEA. Core database and file storage are in Frankfurt, application hosting is in Amsterdam, and backups are held in Frankfurt and Amsterdam.

How is data encrypted?

Traffic uses TLS 1.2 or higher. Stored data and backups use AES-256 encryption. Uploaded files receive the storage provider's encryption plus an additional encryption layer. Passwords are hashed with bcrypt.

Which access controls are available?

CapoFine uses role-based access and least-privilege permissions, secure sessions, temporary one-time magic links, production-access restrictions, audit trails, and MFA through supported SSO identity providers. Exact SSO options depend on the purchased scope.

What happens after a security incident?

Our incident plan covers detection, assessment, containment, investigation, notification, recovery, and post-incident review. When we act as processor, we notify the affected customer without undue delay and, where possible, within 24 hours after becoming aware of a personal data breach.

What are the uptime commitments?

Contracted uptime is package-specific. The standard SLA defines 99.5%, 99.9%, and 99.95% tiers with monitoring, planned-maintenance exclusions, and service credits. The customer's signed order form and SLA determine the applicable commitment.

Is CapoFine ISO 27001 or SOC 2 certified?

CapoFine does not currently claim its own ISO 27001 or SOC 2 certification. Our security programme follows recognised practices, and core infrastructure providers maintain their own certifications. We provide the current assurance scope during review.

Can we review subprocessors and contract controls?

Yes. Our standard DPA provides audit rights, a published subprocessor register, 30 days' notice of new platform subprocessors, and a 14-day reasoned objection period. Contract-specific retention, recovery, support, and service terms remain in the signed agreement.

Start the review

Give your reviewers the evidence.

Request the DPA, subprocessor details, security answers, and applicable SLA so Security, Privacy, Legal, and Procurement can review one consistent set.

  • EEA platform processing
  • Shared responsibility
  • DPA and audit rights
  • SLA commitments in writing