Trust & Security Center

What we do, what we are doing, and what we have not done yet.

HVR holds employment records about real people. This page is written so your security reviewer can check our claims rather than take them on faith.

Practices

Security and privacy practices.

Each module is a practice we operate today. Where a practice is partial, it is described as partial.

Encryption

In transit and at rest, with documented key management. Supporting documents are stored separately from report data.

Access controls

Role-based permissions enforced server-side, SSO for enterprise accounts, and least-privilege defaults for internal staff.

Audit logging

Every read, order, download and configuration change is logged with actor, timestamp and target — including internal access.

Secure document handling

Candidate uploads are scanned, access-scoped to the case, and excluded from report exports unless explicitly attached.

Data minimization

We request the fields a product needs and no more. Fields an employer did not order are not collected.

Data retention

Retention is set per record type and executed on schedule. Deletion is logged; it is not a request that sits in a queue.

Incident response

A documented process with defined severity levels, internal escalation and customer-notification obligations.

Vendor governance

Subprocessors are reviewed before onboarding and listed publicly. Material changes are published.

Accessibility

WCAG 2.2 AA is the design and build target across marketing, employer app and consumer surfaces.

Certifications

Nothing here is a badge.

We display audit status in words, with accurate labels, because a logo implies a completed report.

SOC 2 Type IIIn progressControls implemented; observation period underway. No report is available yet and we will not display a badge until it is.
ISO 27001PlannedScoped for after SOC 2. Not started.
Penetration testingUnder independent reviewAnnual third-party testing; summary letters available under NDA to enterprise prospects.
PCI DSSNot applicableHVR does not store cardholder data. Payment processing is delegated to a PCI-compliant processor.

This area is modular by design

When an audit completes, its report replaces the status row above — the layout already accounts for it. Until then, no trust badge appears anywhere on this site.

Report a vulnerability

We accept reports from security researchers and respond within two business days. Please do not test against production consumer data.

security@hvrscreen.com

Privacy team

Questions about how HVR handles personal information, or about a specific record.

privacy@hvrscreen.com

Compliance team

Permissible purpose, certifications, notices and consumer-rights process questions.

compliance@hvrscreen.com