1. Our commitment
We design TalentMaps with security as a primary requirement. Database-level access controls and narrowly scoped application routes protect the data our customers entrust to us.
2. Infrastructure
TalentMaps uses Supabase-managed PostgreSQL for application data and Vercel for the application layer. Security certifications held by those providers apply to their services; they do not certify TalentMaps itself.
The service is operated on managed cloud infrastructure rather than customer premises.
3. Data encryption
In transit. All communication between your browser and TalentMaps is encrypted using TLS 1.2 or higher. We enforce HTTPS for all connections and use HSTS to prevent downgrade attacks.
At rest. Database and storage encryption are provided by the managed infrastructure providers that store the data.
4. Access control
Row-level security is enforced at the PostgreSQL database layer for customer-owned projects, reports, account data, and cached profile data. An authenticated organisation can read a cached profile only when its projects or recorded enrichment activity reference that profile.
Backend-only company and location caches are not directly readable through authenticated or anonymous customer API roles.
5. Authentication
Account authentication is handled by Supabase Auth. TalentMaps never stores plaintext passwords.
Protected pages and API routes validate the signed-in user on the server before accessing customer data.
6. LinkedIn profile data
Profile enrichment is a point-in-time snapshot. The editor shows when a profile was last refreshed. Freshness guidance labels data as current (under 21 days), refresh soon (21–29 days), or refresh recommended (30 days or older).
Older profile data is not automatically deleted from historical projects. It remains available as part of the customer's project record until that project or account data is deleted, and a recruiter can choose to refresh it. Profile data is processed only to provide requested platform features and is not sold.
7. Vulnerability disclosure
If you discover a security vulnerability in TalentMaps, we ask that you disclose it responsibly by emailing security@talentmaps.app. Please include a clear description of the vulnerability and steps to reproduce it.
We review reports according to their potential impact and will keep the reporter informed as investigation and remediation progress.
Please avoid accessing data that is not yours, disrupting the service, or publicly disclosing a report before there has been a reasonable opportunity to investigate it.
8. Compliance
GDPR. TalentMaps acts as a data processor for EU personal data processed on behalf of our customers, the data controllers. Contact privacy@talentmaps.app to discuss data-protection terms for your organisation.
CCPA. California residents may submit data requests to privacy@talentmaps.app. We do not sell personal data.
Questions about subprocessors or the controls that apply to a particular plan can be sent to security@talentmaps.app.
9. Contact
For security enquiries, vulnerability reports, or questions about our security practices, contact security@talentmaps.app.