Security

Security by design.

We only describe controls that are actually in place. This page is updated as capabilities are verified and released.

Encryption at Rest

Sensitive identifiers and credentials are encrypted with AES-256-GCM before they are stored.

Protected Credentials

Passwords are stored only as salted bcrypt hashes; sessions are regenerated on sign-in.

Private Documents

Uploaded documents are validated by content and never exposed as public links.

Abuse Protection

Rate limiting, request-origin checks and strict input validation on every form.

Audit Trail

Administrative actions and access to personal data are recorded.

This website and recruitment portal

  • National ID numbers are encrypted (AES-256-GCM) and matched for duplicate applications using a keyed hash, never stored in clear text.
  • Uploaded CVs and documents are checked by their real content, stored under generated names and are only available to signed-in AnnCore administrators.
  • Administrator sessions use secure, HTTP-only cookies, expire after inactivity and are protected against cross-site request forgery.
  • Forms are rate-limited and validated on the server, and the site sends a restrictive Content Security Policy.
  • Administrative changes and access to exported or stored personal data are recorded in an audit log.

AnnCore products

Security capabilities of AnnCore HR and AnnCore Legal depend on the product and the deployment model (Cloud SaaS or On-Premise). We share the relevant security documentation during evaluation and on request.

Reporting a vulnerability

If you believe you have found a security issue, please contact us through the contact page with the subject โ€œSecurityโ€. Please do not access data that is not yours.

Contact us