SourcingOS Trust Center

Trust should be inspectable.

SourcingOS is built for evidence-heavy recruiting work. Security, candidate-data handling, AI behavior, provenance, and recruiter control should be explained with the same discipline we expect from candidate evidence.

Control register last reviewed: 2026-09-06

Security

Protected routes fail closed, privileged actions are authorized server-side, sensitive database functions are restricted, and security checks run continuously in CI.

Security architecture

Responsible AI

External resumes, webpages and provider text are treated as untrusted evidence. They cannot redefine agent permissions or silently trigger consequential recruiter actions.

Responsible AI

Candidate data & provenance

Evidence may come from reviewed public sources, recruiter-imported data, or connected providers. SourcingOS keeps source/provenance and confidence boundaries attached instead of pretending every field has equal authority.

Privacy Data sources

Human control

Identity confirmation, contactability and other consequential workflow actions remain distinct from retrieval evidence. Unknown evidence stays unknown; it is not silently converted into a negative or a verified fact.

Methodology

Current control status

These statements are intentionally narrower than a marketing badge. They are the controls we can support today without implying certifications we have not obtained.

Verified · edge

Edge firewall and DDoS mitigation

Production edge firewall and DDoS mitigation are active.

Implemented · identity

Fail-closed authentication and authorization

Protected routes fail closed and privileged actions require server-side authorization.

Verified · data

Privileged database function isolation

Sensitive database functions are restricted to intended privileged roles.

Implemented · sdlc

Continuous security CI

Code and dependency security checks run continuously in CI.

Implemented · ai

Outbound URL / SSRF guard

Server-side outbound URL access is constrained by an SSRF guard.

Implemented · ai

Untrusted-content AI boundary

External content is treated as untrusted evidence and cannot redefine agent permissions.

Implemented · ai

Recruiter-controlled consequential actions

Consequential recruiting actions remain under recruiter control.

Implemented · vendors

Provider spend circuit breakers

Provider calls are governed by spend and circuit-breaker controls.

Trust rules that shape the product

No fake candidates

SourcingOS does not invent people, companies, links or contact data to fill a slate. Empty or uncertain evidence is surfaced as such.

Signals are not verification

Clearance language in a public bio, a credential breadcrumb, open-to-work phrasing, or a possible identity match remains a signal until the appropriate verification step supports it.

No silent identity merge

Source identities remain reviewable and recruiter-controlled. High similarity is evidence for a proposed match, not permission to silently collapse records.

No external-text authority

A resume or webpage can contain useful evidence and also malicious instructions. External text is data; it does not gain authority to call tools, change system policy, reveal secrets, or approve actions.

Requirement truth

SourcingOS distinguishes recruiter requirements from synonyms, discovery expansions, inferences and missing evidence. A discovery term cannot silently satisfy a hard requirement.

What we are not claiming yet

Gated

Upload validation and quarantine contract

Upload validation and quarantine controls are implemented; malware-scanning claims remain gated until operationally verified.

Planned

Backup restore exercises

Formal restore exercises are planned and are not yet represented as a completed control.

SourcingOS does not currently display SOC 2, ISO 27001, FedRAMP, HIPAA, or similar certification badges. Those claims belong here only after the underlying audit or authorization actually exists.

Report a security or privacy issue

Security researchers and people with candidate-data or privacy questions can use the existing private contact channel. Do not include passwords, access tokens, API keys, or unnecessary personal data in the initial report.

Responsible disclosure Contact SourcingOS