Security

Security is not just a feature.

It's the foundation everything else is built on. pace handles sensitive candidate data and high-stakes hiring decisions — our security practices reflect that responsibility.

Encryption

Protecting data where
it matters most.

01

TLS via Hosting Platform

In Transit

All data transmitted between clients and our servers is encrypted using TLS, managed and enforced by our hosting platform (Replit). We rely on the platform's certificate management and TLS termination rather than managing our own certificate infrastructure.

02

AES-256-GCM for Sensitive Fields

At Rest

Sensitive fields — such as TOTP secrets and two-factor authentication tokens — are encrypted using AES-256-GCM with authenticated encryption. Passwords are hashed using bcrypt. We do not currently operate a dedicated key management service (KMS) or automated key rotation — encryption keys are managed via environment variables.

Infrastructure

Honest about where
we stand today.

01

Managed Cloud Hosting

pace is hosted on Replit, a managed cloud platform. Infrastructure provisioning, OS-level security patches, and networking are handled by the platform. We do not self-manage servers, VPCs, or availability zones.

02

Platform-Level Protections

Network-level protections such as DDoS mitigation and traffic management are provided by the hosting platform. We do not currently configure our own WAF, network segmentation, or firewall rules at the application level.

03

Penetration Testing

Roadmap

We have not yet conducted formal third-party penetration testing. This is on our roadmap as we mature our security programme and scale enterprise operations.

04

Dependency Management

Roadmap

We monitor software dependencies for known vulnerabilities using standard tooling. We do not currently have automated CI/CD security gates that block deployments — this is an area we plan to strengthen.

Access Controls

Trust is earned through
discipline, not promises.

01

Role-based access with MFA support.

Identity

Access is controlled through role-based permissions (manager and interviewer roles). Multi-factor authentication (TOTP) is available for all users. Sessions use httpOnly, secure cookies with cryptographically random session identifiers. We do not currently have automated access reviews or short-lived credential systems.

02

Tenant isolation via middleware.

Data Access

Each organisation's data is isolated through application-level middleware that enforces company context on every request. This is middleware-enforced isolation, not architectural separation — all tenants share the same database with scoped queries. Cross-tenant access is prevented by the middleware layer.

03

SOC 2 Type II is planned.

SOC 2

We have not yet begun a formal SOC 2 audit. As we grow and serve enterprise customers, achieving SOC 2 Type II certification is on our roadmap. We are building foundational controls now — access management, session handling, and audit logging — that will support a future engagement.

Incident Response

Building our response
capability transparently.

1

Detect

We do not currently have automated monitoring, SIEM, or real-time alerting systems in place. Anomaly detection is manual. Building automated monitoring is on our roadmap.

2

Respond

We are developing documented incident response procedures. We do not currently have a formal on-call rotation or 24/7 coverage. Response is handled by the engineering team during business hours.

3

Notify

In the event of a confirmed data breach, we are committed to notifying affected customers within 72 hours in line with GDPR Article 33 requirements. Notification templates and processes are being formalised.

4

Improve

We conduct post-incident reviews to identify root causes and improve processes. As we mature, we plan to formalise blameless post-mortem practices and systematic control improvements.

Frequently Asked

Questions buyers ask before they trust us with hiring data.

Who at pace can see our interview recordings and transcripts?

Production access is limited to a small number of engineers on a least-privilege basis. Within the application, access is constrained by role-based permissions (manager and interviewer roles) and tenant-isolation middleware that scopes every query to the customer's organisation. Files in object storage record their owning company at upload time, and every download request re-checks that the requester belongs to that company before the object is served — so a leaked or guessed link cannot be opened by anyone outside the owning organisation. Sensitive workspace actions write to an internal audit log so we can reconstruct who did what and when.

What happens if one of your sub-processors is breached?

If a sub-processor (Anthropic, Resend, Google Cloud Storage, or Replit) notifies us of a security incident affecting your data, we treat it as our own incident: we assess the blast radius against our processing records, contain any onward exposure, and notify affected customers. For confirmed personal-data breaches we commit to GDPR Article 33 timing — notification within 72 hours of becoming aware. We will share what we know, what we don't yet know, and what we are doing about it, rather than waiting for a polished narrative.

Do you support SAML SSO and SCIM today?

Honestly: not yet. Sign-in today is via email and password (with TOTP-based two-factor available) and OAuth through Google or LinkedIn. SAML 2.0 SSO and SCIM provisioning are on the roadmap for enterprise tiers but are not shipped. If SAML or SCIM is a hard procurement requirement for you, tell us — it helps us prioritise, and we will be straight with you about timing rather than overpromise.

What admin actions are written to your audit log?

The audit log captures workspace actions that change the state of hiring data or who can see it: candidate lifecycle events (creation, stage changes, decisions, archival, deletion, anonymisation), score submissions and edits, interview lifecycle (creation, completion, archival, deletion, retry of analysis), job and role changes, competency edits (including AI-generated vs user-edited), team-membership changes (invitations, role changes, removals), transcript views, committee report exports, billing-state changes (subscription, refunds, disputes), and screening question updates. Each entry records the actor, the affected resource, the action, and a timestamp. Authentication events (login, password reset, two-factor enrolment) are not yet in the audit log — that gap is on our roadmap. We use the log for our own incident response today and plan to expose a customer-facing view of admin actions to managers in a future release.

Get Started

Security you can
verify yourself.

Try pace free and see our security practices firsthand. Questions? Our team is ready to walk through our architecture with you.

Start free trial