Trust should be inspectable.
SourcingOS is built for evidence-heavy recruiting work. Security, candidate-data handling, AI behavior, provenance, and recruiter control should be explained with the same discipline we expect from candidate evidence.
Control register last reviewed: 2026-09-06
Security
Protected routes fail closed, privileged actions are authorized server-side, sensitive database functions are restricted, and security checks run continuously in CI.
Responsible AI
External resumes, webpages and provider text are treated as untrusted evidence. They cannot redefine agent permissions or silently trigger consequential recruiter actions.
Candidate data & provenance
Evidence may come from reviewed public sources, recruiter-imported data, or connected providers. SourcingOS keeps source/provenance and confidence boundaries attached instead of pretending every field has equal authority.
Human control
Identity confirmation, contactability and other consequential workflow actions remain distinct from retrieval evidence. Unknown evidence stays unknown; it is not silently converted into a negative or a verified fact.
Current control status
These statements are intentionally narrower than a marketing badge. They are the controls we can support today without implying certifications we have not obtained.
Edge firewall and DDoS mitigation
Production edge firewall and DDoS mitigation are active.
Fail-closed authentication and authorization
Protected routes fail closed and privileged actions require server-side authorization.
Privileged database function isolation
Sensitive database functions are restricted to intended privileged roles.
Continuous security CI
Code and dependency security checks run continuously in CI.
Outbound URL / SSRF guard
Server-side outbound URL access is constrained by an SSRF guard.
Untrusted-content AI boundary
External content is treated as untrusted evidence and cannot redefine agent permissions.
Recruiter-controlled consequential actions
Consequential recruiting actions remain under recruiter control.
Provider spend circuit breakers
Provider calls are governed by spend and circuit-breaker controls.
Trust rules that shape the product
No fake candidates
SourcingOS does not invent people, companies, links or contact data to fill a slate. Empty or uncertain evidence is surfaced as such.
Signals are not verification
Clearance language in a public bio, a credential breadcrumb, open-to-work phrasing, or a possible identity match remains a signal until the appropriate verification step supports it.
No silent identity merge
Source identities remain reviewable and recruiter-controlled. High similarity is evidence for a proposed match, not permission to silently collapse records.
No external-text authority
A resume or webpage can contain useful evidence and also malicious instructions. External text is data; it does not gain authority to call tools, change system policy, reveal secrets, or approve actions.
Requirement truth
SourcingOS distinguishes recruiter requirements from synonyms, discovery expansions, inferences and missing evidence. A discovery term cannot silently satisfy a hard requirement.
What we are not claiming yet
Upload validation and quarantine contract
Upload validation and quarantine controls are implemented; malware-scanning claims remain gated until operationally verified.
Backup restore exercises
Formal restore exercises are planned and are not yet represented as a completed control.
SourcingOS does not currently display SOC 2, ISO 27001, FedRAMP, HIPAA, or similar certification badges. Those claims belong here only after the underlying audit or authorization actually exists.
Report a security or privacy issue
Security researchers and people with candidate-data or privacy questions can use the existing private contact channel. Do not include passwords, access tokens, API keys, or unnecessary personal data in the initial report.