Security Policy

Effective date: July 27, 2026

Nahag+ takes the security of your personal data seriously. This policy summarizes the technical and organizational measures we use to protect your information.

1. Encryption

  • Data in transit is encrypted using TLS 1.2+.
  • Data at rest (including resumes, interview data, and voice recordings) is encrypted using industry-standard encryption (e.g., AES-256).

2. Access Controls

  • Access to production systems and user data is restricted to authorized personnel on a need-to-know basis.
  • We use role-based access control (RBAC) and, where applicable, multi-factor authentication (MFA) for internal systems.

3. Infrastructure Security

Our infrastructure is hosted with reputable cloud providers that maintain independent security certifications. We apply the principle of least privilege for service-to-service authentication (e.g., service role keys are scoped and never exposed client-side).

4. Monitoring and Incident Response

  • We monitor systems for suspicious activity and maintain logging for security review.
  • In the event of a data breach affecting personal data, we will notify affected users and relevant regulators as required by applicable law (e.g., within 72 hours under GDPR/UK GDPR where feasible, or as required under PIPEDA's "real risk of significant harm" standard).

5. Vendor and Subprocessor Management

We vet third-party service providers (e.g., cloud hosting, payment processing, email delivery, AI model providers) for appropriate security and data protection commitments and enter into data processing agreements where required.

6. Your Role in Security

You can help keep your account secure by using a strong, unique password, enabling any available account security features, and not sharing your login credentials.

7. Reporting a Security Issue

If you discover a potential vulnerability, please report it responsibly to support@nahagplus.com. We appreciate good-faith security research conducted without accessing or modifying other users' data.