Security is the foundation

Candidate information is held under least privilege, separated by organization and by candidate, and every access is attributed to a person and a purpose.

Three-level record classification

Standard

Governed operational records available to authorized members of the organization.

Restricted

Candidate-identifying and assessment-content records, limited to explicitly authorized roles.

Protected

Accommodation, exception, health-adjacent and sensitive records. Least-privilege access only, always audited, and never used as assessment evidence.

Platform controls

  • Tenant isolation
  • Organization isolation
  • Candidate isolation
  • Authority enforcement
  • Three-level record classification
  • Row level security
  • Private storage
  • Server-side secrets
  • Audit attribution
  • Session security
  • Secure invitations
  • Cross-product isolation
  • Least privilege

Identity

  • Passkeys
  • Multi-factor authentication
  • Step-up authentication for protected records

A device may use its own biometric verification to unlock a passkey. Talent Assessment and ASCEND never receive or store a device's Face ID, fingerprint or biometric template.

Integration credentials

  • Scoped credentials — never a broad unrestricted key
  • Organization scope
  • Product scope
  • Least privilege
  • Expiration
  • Rotation
  • Revocation
  • Rate limiting
  • Audit attribution
  • Webhook signing
  • Integration health

Accessibility

  • Semantic landmarks and a single H1 per page
  • Visible focus on every interactive element
  • Contrast held against the approved palette
  • Full keyboard operation, including navigation and dialogs
  • Motion kept restrained and non-essential
  • Authorized adjustments honored without disclosure to reviewers