Trust starts with how we handle your data

Security isn't a page.
It's how we operate.

Every résumé, offer letter, and comp figure you share with Crimson Talent lives inside a security program built to enterprise standard — independently audited, encrypted end-to-end, and watched around the clock by our own team.

Independently attested & certified
SOC 2 Type IIAudited by Schellman
ISO/IEC 27001Information security
ISO/IEC 27701Privacy management
GDPR & CCPAPrivacy-law ready

Four principles behind
every control we run.

We treat candidate and client data the way a bank treats money — with least privilege, defense in depth, and the assumption that trust must be continuously earned.

Least privilege by default

No one — employee or system — gets access they don't need. Role-based access control, mandatory SSO/MFA, and just-in-time elevation govern every request to candidate data.

Defense in depth

Encryption, network segmentation, continuous monitoring, and independent testing stack so that no single failure exposes your information. Every layer assumes the one before it can fail.

Continuously verified

Trust is never assumed. Annual third-party audits, ongoing penetration testing, a live bug-bounty program, and 24/7 monitoring keep our posture honest — not just at audit time.

Transparent by design

You can request our SOC 2 report, penetration-test summary, and DPA under NDA. Our subprocessor list is public, and our status page is always live. No black boxes.

A 24/7 Security Operations Center
and a dedicated Purple Team.

Security at Crimson Talent is a 14-person organization led by our CISO — not an outsourced afterthought. Two functions sit at its core.

Always on

Security Operations Center (SOC)

Our in-house SOC monitors every system, log, and access event around the clock. A SIEM correlates signals in real time; analysts triage alerts, hunt for threats, and respond before issues become incidents.

24/7/365 monitoring & alerting via centralized SIEM
Proactive threat hunting & anomaly detection
Defined incident-response runbooks & escalation paths
<15min
Mean time to detect
99.9%
Platform uptime SLA
Offensive + Defensive

The Purple Team

Most firms keep attackers (Red) and defenders (Blue) apart. We merge them into one Purple Team — six specialists who continuously attack our own systems and immediately harden what they break.

Red
Simulates real attacks — phishing, exploitation, privilege escalation.
+
Blue
Detects, defends, and hardens — turning every finding into a fix.
6
Purple Team specialists
24×
Internal exercises / year

Encrypted everywhere.
Stored only in the US.

Candidate and client data is hosted entirely within US regions of Amazon Web Services (us-east-1 / us-west-2) — SOC-compliant data centers your information never leaves.

TLS 1.3 in transitEvery connection encrypted end-to-end
Segmented environmentsProd · staging · dev fully isolated
AES-256 at restKeys managed in AWS KMS (HSM-backed)
Encrypted, tested backupsAutomated DR with defined RPO/RTO

Data minimization & retention

We collect only what a search requires and delete candidate data on a defined retention schedule — or immediately on request.

Your rights, honored

Access, correction, and deletion requests under GDPR & CCPA are handled by our Data Protection Officer — no dark patterns, no delays.

We never sell your data

Candidate information is used to represent you — full stop. It is never sold, rented, or shared with third parties for marketing.

Vetted people & vendors

Every employee passes background checks and annual security training; every subprocessor is reviewed and published on our list.

24/7
Security Operations Center coverage
99.9%
Platform uptime service level
<72h
Breach notification commitment
100%
Staff completing annual security training

Attested by independent auditors.

Our controls are validated by third parties — not self-declared. Reports are available to clients and prospects under NDA through the Trust Center.

SOC 2 Type II

Audited by Schellman, a leading independent CPA firm, against the Security, Availability, and Confidentiality Trust Services Criteria — covering operating effectiveness over time, not a point-in-time snapshot.

Report available under NDA
ISO27001

ISO/IEC 27001 & 27701

Our Information Security Management System is certified to ISO 27001, extended with the ISO 27701 privacy module — a globally recognized framework for managing information and personal-data risk.

Certified & surveilled annually
GDPR

GDPR & CCPA readiness

We honor data-subject rights, maintain a public subprocessor list, sign DPAs on request, and appoint a Data Protection Officer — aligning to both EU and California privacy law.

DPA available on request

NIST CSF alignment

Our program is mapped to the NIST Cybersecurity Framework — Identify, Protect, Detect, Respond, Recover — giving structure to how we assess and mature our controls year over year.

Continuously assessed

If something happens,
we're already moving.

A documented, rehearsed incident-response plan means the question is never "what do we do?" — it's already answered before an alert fires.

Phase 01

Detect

SIEM and SOC analysts identify and triage the signal, classifying severity within minutes.

Continuous · 24/7
Phase 02

Contain

Affected systems are isolated and access revoked to stop spread while evidence is preserved.

Immediate
Phase 03

Notify

Impacted clients are informed with clear facts — our commitment is notification within 72 hours.

< 72 hours
Phase 04

Recover & learn

Service is restored from tested backups, followed by a blameless post-incident review and hardening.

Post-incident
Responsible Disclosure

Found something? Tell us.

We welcome reports from security researchers. If you believe you've found a vulnerability, contact our security team directly — we run a coordinated disclosure program and a private bug bounty.

security@crimsontalent.com · PGP: 4A9F 2C11 8E7D 55B0  9C33 71EA F208 6BD4 1A55 90CE
Email the security team
Trust Center

Request our documentation.

Prospective and current clients can request our security documentation package under NDA. Everything you need for vendor review, in one place.

SOC 2 Type II report
Penetration-test executive summary
Data Processing Agreement (DPA)
Security whitepaper & subprocessor list
Request documents

Security FAQ.

All candidate and client data is hosted within US regions of Amazon Web Services (us-east-1 and us-west-2). Your data does not leave the United States. Our subprocessors are US-based or contractually bound to equivalent protections.
They're two different things. Our SOC (Security Operations Center) is the in-house team monitoring our systems 24/7. SOC 2 is an independent audit standard — attested by Schellman — that validates the design and operating effectiveness of our security controls over time.
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Encryption keys are managed in AWS KMS, backed by hardware security modules (HSMs), with strict access controls and rotation.
Yes. Under GDPR and CCPA you can request access, correction, or deletion of your personal data at any time. Our Data Protection Officer handles these requests directly — email privacy@crimsontalent.com.
Never. We use your information solely to represent you in a search. We do not sell, rent, or share candidate data with third parties for marketing under any circumstances.
Clients and qualified prospects can request our SOC 2 Type II report, penetration-test summary, and DPA under NDA through the Trust Center above, or by emailing trust@crimsontalent.com.