Protecting verified candidate records, evaluation sandboxes, and enterprise HRMS data with transparent, defense-in-depth engineering practices.
Security at LetGetIn is designed as a foundational layer. We combine defense-in-depth principles, automated runtime sandbox isolation, and continuous vulnerability assessments to safeguard sensitive candidate and enterprise data.
All data transmitted between your browser and LetGetIn services is encrypted in transit using modern Transport Layer Security (TLS 1.2+ / HTTPS). Sensitive database stores are encrypted at rest using industry-standard cryptographic algorithms.
Access to production environments and user data is strictly limited to authorized personnel based on the principle of least privilege. Administrative access requires multi-factor authentication (MFA) and is audited continuously.
User accounts are protected through cryptographically salted password hashes and secure session management. Enterprise SSO and SAML integrations enable organizations to enforce centralized corporate identity policies.
Our applications run on tier-1 cloud infrastructure providers with physical data center security, automated DDoS mitigation, redundant power, and automated backup routines.
Candidate code execution sandboxes are executed in containerized, air-gapped runtimes with restricted system call interfaces, strict memory/CPU quotas, and zero direct access to internal database networks.
We maintain real-time application monitoring and telemetry to identify anomalous traffic patterns, detect potential brute-force attempts, and track service reliability.
Our engineering workflow incorporates automated linting, type-checking, code review gates, and continuous static analysis (SAST) prior to code deployment.
We adhere to privacy-by-design principles, minimizing data collection to only what is necessary to perform objective skill benchmarking and HRMS operations.
LetGetIn maintains a documented incident response protocol outlining triage, containment, resolution, and communication procedures in the event of an operational anomaly.
We evaluate third-party cloud infrastructure vendors, email gateways, and payment partners against rigorous security, availability, and privacy benchmarks.
We value the contributions of the security research community. If you discover a potential vulnerability in our platform, we invite you to report it to us responsibly.
If you believe you have found a security vulnerability or have questions regarding our technical architecture, please contact our security engineering group: