Trust

Trust at AuraSync

Hiring data is sensitive. This page summarizes how AuraSync secures it, who can access it, how long it is kept and how it is deleted. The Privacy Policy and Terms of Service are the authoritative versions of everything below.

Security controls

The platform is protected by layered technical controls:

  • All traffic uses HTTPS with TLS 1.2 or higher.
  • Passwords are hashed; OAuth tokens and other credentials are encrypted at rest.
  • Production credentials are held in a managed secret store, not in code.
  • Service-to-service calls are authenticated.

Access control and data isolation

Each customer organization's data is held in its own database, so one customer's data is never reachable from another's workspace.

Access to production systems is restricted to authorized personnel and is logged. Within a customer's workspace, results go to the hiring organization the candidate applied to; facial verification data is not shared with that organization at all.

Data handling and sub-processors

AuraSync is a business-to-business platform. When an organization uses AuraSync to hire, that organization decides what data is collected and why, and Genesis Technologies processes it on their instructions.

AuraSync relies on a small set of named sub-processors for hosting, AI processing, video, payments and optional integrations, each under a written contract. Customers receive at least 30 days' notice before a sub-processor is added or replaced. AuraSync does not sell personal data and does not use candidate data to train its own AI models.

Data retention

Default retention periods, as set out in the Privacy Policy:

  • Candidate application data: the hiring cycle plus one year, unless the customer sets a shorter period.
  • Assessment results and scores: the application plus 90 days.
  • Facial embeddings for identity verification: deleted within 90 days of capture by an automated purge.
  • Audit and activity logs: two years.
  • Backups: up to 90 days after deletion from the live system.

Deletion and individual rights

Individuals can ask to access, correct or erase their personal data, and can withdraw consent at any time, as easily as it was given. Withdrawing facial verification consent erases the stored facial and audio baselines immediately.

Requests are acknowledged within 48 hours and answered within 30 days. Candidates can also ask the organization they applied to, which is usually responsible for their application data.

Integrations

AuraSync connects to other systems only where a customer chooses to:

  • Mailbox and calendar (Google or Microsoft): optional, ATS-only, used to show candidate correspondence and schedule interviews. Mailbox data is deleted on disconnect.
  • The Assessment module has no Google connection, and no data obtained from Google APIs is sent to it or to any AI provider.
  • Salesforce and ServiceNow: used for sign-on or as a UI host where a customer uses them. The Salesforce package renders the ATS in an iframe and does not read or write Salesforce CRM data.

Auditability

The ATS keeps an audit trail of sign-ins and significant actions. Every candidate consent is recorded with the version of the notice shown at the time, so it is always possible to say what was agreed to and in what words.

Assessment results are stored with the application, so a hiring decision can be reviewed later against the evidence it was based on.

Security incidents

Reportable cyber security incidents are reported to CERT-In within six hours of AuraSync becoming aware of them. Affected customers are notified within 24 hours so they can meet their own obligations, and affected individuals are informed without delay.

Frequently Asked Questions

Is customer data isolated from other customers?+

Yes. Each customer organization's data is held in its own database, so one customer's data is never reachable from another's workspace.

Does AuraSync use customer or candidate data to train AI models?+

No. AuraSync does not use candidate or assessment data to train its own AI models, and its AI providers act as processors under contract and may not use the data for their own purposes.

How long does AuraSync keep assessment data?+

Assessment results and scores are kept with the application under the retention schedule of the organization the candidate applied to; the default is the application plus 90 days. Facial embeddings are deleted within 90 days of capture.

How can a candidate have their data deleted?+

By contacting the organization they applied to or AuraSync directly. Requests are acknowledged within 48 hours and answered within 30 days, and deleted data leaves backups within 90 days.