AES-256 / TLS 1.3
Full bank-grade encryption at rest and in transit across all candidate records and files.
SOC-2 Type II Certified
Hosted in certified cloud data centers with 99.9% uptime SLA and automated DDoS mitigation.
Zero AI Model Training
Enterprise zero-data-retention agreements prevent your documents from training foundational models.
01.Cryptographic Architecture & Encryption
Every piece of confidential career intelligence stored within Ampply is secured across the entire transmission and storage lifecycle:
Encryption in Transit (TLS 1.3 & HSTS)
All HTTP communications between your browser, our API gateways, and downstream microservices enforce TLS 1.3 with modern cipher suites and HTTP Strict Transport Security (HSTS) with preloading.
Encryption at Rest (AES-256)
Database volumes, object storage clusters (containing resume PDFs and cover letter artifacts), and automated database snapshots are encrypted with AES-256 encryption managed via secure key management systems.
02.AI Model Privacy & Zero Retention
When utilizing Ampply's ATS diagnostic simulator, STAR tailoring synthesizer, or AI Mock Interview Studio:
- No Training on Candidate Data: Model providers (including Google Gemini Enterprise) contractually cannot and do not use your submitted resumes, prompts, or interview transcripts to train, fine-tune, or calibrate models.
- Zero In-Flight Retention: Inference prompts and outputs exist only in transient memory during generation and are discarded immediately upon stream completion.
- Enterprise Isolated Endpoints: API calls bypass public consumer consumer-facing queues and execute on dedicated enterprise virtual private clouds.
03.Identity Governance & Tenant Isolation
Candidate accounts are partitioned using logical multi-tenant isolation with strict Row-Level Security (RLS) enforcement at the database layer. No user can access or query another candidate's pipeline, notes, compensation targets, or documents.
Authentication Safeguards
Passwordless authentication, industry-standard OAuth 2.0 flows, cryptographic JWT signature validation, and secure HttpOnly cookie flags prevent session hijacking.
Access Boundaries
Ampply engineering staff have zero access to unencrypted candidate resumes or mock studio transcripts, adhering to strict least-privilege administrative protocols.
04.Continuous Vulnerability Management
- Static & Dynamic Code Analysis: Automated continuous integration security scanning tests all codebase changes against OWASP Top 10 vulnerabilities before deployment.
- Dependency Scanning: Real-time dependency vulnerability audits identify and patch upstream CVEs within hours of disclosure.
- Automated Backups & Disaster Recovery: Hourly encrypted off-site database backups with geographic multi-region replication.
Responsible Vulnerability Disclosure
If you are a security researcher and believe you have identified a vulnerability within the Ampply platform, please report it immediately to our Security Operations Center at: