Enterprise Security & Infrastructure

Security & Compliance

Ampply implements multi-tenant cryptographic isolation, end-to-end encryption, SOC-2 certified infrastructure, and zero-retention AI model integration to safeguard your career data.

Last Updated: September 26, 2026•Version 2.3

AES-256 / TLS 1.3

Full bank-grade encryption at rest and in transit across all candidate records and files.

SOC-2 Type II Certified

Hosted in certified cloud data centers with 99.9% uptime SLA and automated DDoS mitigation.

Zero AI Model Training

Enterprise zero-data-retention agreements prevent your documents from training foundational models.

01.Cryptographic Architecture & Encryption

Every piece of confidential career intelligence stored within Ampply is secured across the entire transmission and storage lifecycle:

Encryption in Transit (TLS 1.3 & HSTS)

All HTTP communications between your browser, our API gateways, and downstream microservices enforce TLS 1.3 with modern cipher suites and HTTP Strict Transport Security (HSTS) with preloading.

Encryption at Rest (AES-256)

Database volumes, object storage clusters (containing resume PDFs and cover letter artifacts), and automated database snapshots are encrypted with AES-256 encryption managed via secure key management systems.

02.AI Model Privacy & Zero Retention

When utilizing Ampply's ATS diagnostic simulator, STAR tailoring synthesizer, or AI Mock Interview Studio:

Enterprise Inference Guarantees
  • No Training on Candidate Data: Model providers (including Google Gemini Enterprise) contractually cannot and do not use your submitted resumes, prompts, or interview transcripts to train, fine-tune, or calibrate models.
  • Zero In-Flight Retention: Inference prompts and outputs exist only in transient memory during generation and are discarded immediately upon stream completion.
  • Enterprise Isolated Endpoints: API calls bypass public consumer consumer-facing queues and execute on dedicated enterprise virtual private clouds.

03.Identity Governance & Tenant Isolation

Candidate accounts are partitioned using logical multi-tenant isolation with strict Row-Level Security (RLS) enforcement at the database layer. No user can access or query another candidate's pipeline, notes, compensation targets, or documents.

Authentication Safeguards

Passwordless authentication, industry-standard OAuth 2.0 flows, cryptographic JWT signature validation, and secure HttpOnly cookie flags prevent session hijacking.

Access Boundaries

Ampply engineering staff have zero access to unencrypted candidate resumes or mock studio transcripts, adhering to strict least-privilege administrative protocols.

04.Continuous Vulnerability Management

  • Static & Dynamic Code Analysis: Automated continuous integration security scanning tests all codebase changes against OWASP Top 10 vulnerabilities before deployment.
  • Dependency Scanning: Real-time dependency vulnerability audits identify and patch upstream CVEs within hours of disclosure.
  • Automated Backups & Disaster Recovery: Hourly encrypted off-site database backups with geographic multi-region replication.

Responsible Vulnerability Disclosure

If you are a security researcher and believe you have identified a vulnerability within the Ampply platform, please report it immediately to our Security Operations Center at:

[email protected] • PGP Fingerprint available upon request • 24-hour response SLA