TalentDocket Discuss the pilot

Security

Security implementation exists. Release assurance is still bounded.

This page separates repository controls from customer-facing availability. Passing local tests does not promote a capability or create a certification, residency commitment or production assurance.

Append-only history

Currently gated

The repository models corrections as new events with actor, timestamp and reason. The affected financial workflows remain release-gated.

Tenant isolation

Bounded pilot

Database row-level security and tenant-scoped records are implemented, while signed-in access remains a bounded pilot.

Least-privilege roles

Currently gated

Role-based access is in bounded pilot; external-accountant sessions and their end-to-end release evidence remain gated.

No fabricated data

Bounded pilot

Released pilot surfaces must show an error or empty state rather than substituting sample business data.

Traceable analytics

Currently gated

The analytics design exposes source, freshness and exclusions, but authoritative dashboards are currently gated.

Your data, exportable

Currently gated

Versioned CSV/XLSX packages exist in repository tests, but accountant exports are not released.

Detail

The controls, specifically.

Tenant isolation

Tenant-scoped PostgreSQL row-level security is implemented and covered by repository tests. Authentication and core records remain bounded pilot capabilities, so this is implementation evidence rather than a general availability or independent-assurance claim.

Access control

JWT authentication and role-based access are in bounded pilot. External accountant invitations and the full authorization matrix remain gated by their role, assistive, staging and professional-review evidence. They are not presented as generally available here.

Audit trail

Append-only contract, invoice, collection and payment evidence is implemented in the repository. Those customer workflows remain disabled, so the audit model is not yet a released end-to-end dispute assurance.

Uploaded files

Quarantine-first storage and malware-scanner integration are implemented. Contract and publication-evidence workflows still have scanner, provider, browser, role and staging gates; clean production upload behavior is not claimed until those pass.

Data protection

Privacy request, retention, access and grievance operations remain disabled pending counsel-approved policies, staging drills and independent security review. No contractual India data-residency commitment is published for the current pilot.

What we do not claim

TalentDocket holds no security certifications. We have not completed SOC 2, ISO 27001 or an equivalent audit, and we will not imply otherwise on a marketing page. If your procurement process requires a certification, tell us early — the honest answer today is that we do not have one.

We also do not take custody of funds, hold banking credentials, or connect to your bank accounts. There is no money in the system to steal, only records of money that moved elsewhere.

Reporting a vulnerability

Email hello@talentdocket.com with details and we will acknowledge it. Please give us a reasonable window to fix an issue before disclosing it publicly.

Due diligence

Send us your security questionnaire.

We'll fill it in properly, including the questions where the answer is 'not yet'. That is more useful to both of us than a confident blank.