Security

Security

How Cntrlall keeps each agency's candidates and documents private.

Last updated 6 October 2026

Every agency is walled off

Each workspace belongs to one agency. Every candidate, job, document and client format carries that agency's ID, and every query, update and download is checked against the signed-in user's agency on the server — not just hidden in the interface.

Inside a workspace, recruiters do the work and agency admins manage the team. Only admins can add or remove users.

Files are never public

Resumes, client formats and generated documents are kept in private storage, never as public links. A file is only returned to a signed-in member of the agency it belongs to, and is sent with no-store caching.

Sign-in

Passwords must be at least 12 characters with letters and numbers, and are stored only as a bcrypt hash. Login and signup attempts are rate limited. A user's role, agency and account status are re-checked against the database on every workspace request, not trusted from the browser.

In transit and in the browser

All traffic uses HTTPS with HSTS. Pages send a strict Content Security Policy. Requests that change data must come from Cntrlall itself, and outgoing webhooks cannot reach private networks.

Where data lives

Records are stored in a managed cloud database and files in private storage. AI requests carry only the text that request needs.

Deleting data

Candidates can be deleted from the workspace at any time. Whole workspaces, users and documents are deleted on request; see the Privacy page for how.

Report a problem

If you find a security issue, email support@cntrlall.com with the details. We reply within two business days and will not take action against good-faith research.