CVPRO protects sensitive candidate and client information with industry-leading security practices. Your trust is our responsibility.
Military-grade encryption protecting your data at every layer
All stored data is encrypted using AES-256 (Advanced Encryption Standard with 256-bit keys), the same encryption standard used by financial institutions and government agencies worldwide.
All communication between clients and CVPRO servers is protected using TLS 1.3 (Transport Layer Security), the latest and most secure version.
Direct database connections are established over encrypted channels with SSL/TLS verification.
India's Digital Personal Data Protection Act 2023 compliance
CVPRO is fully aligned with the Digital Personal Data Protection Act (DPDPA) 2023, India's comprehensive data protection legislation. We implement strict controls to protect personal data across recruitment workflows.
Secure hosting and database architecture
CVPRO infrastructure is hosted entirely within India on secure, dedicated servers meeting enterprise standards.
PostgreSQL database with advanced security features and multi-tenant architecture.
Robust application server configuration with load balancing and security hardening.
How your data interacts with AI services
CVPRO uses Anthropic's Claude API for resume evaluation and candidate assessment capabilities. We maintain strict data protection practices when using this service.
Your customer data, candidate information, and confidential hiring data are NEVER used to train or improve the Claude model. Anthropic does not retain your data for model improvement.
Data is processed in real-time by the API and not stored by Anthropic after the request completes. Only the minimum necessary information is sent for evaluation purposes.
Personally Identifiable Information (PII) can be redacted from evaluation requests, ensuring additional protection of sensitive candidate information while maintaining evaluation accuracy.
Only data relevant to the specific evaluation task is transmitted to the API. Unnecessary information is filtered before transmission.
Role-based access and authentication
CVPRO implements granular role-based access control with six distinct roles, each with specific permissions and capabilities.
Full system access, user management, system configuration
Organization management, user invitations, team settings
View and evaluate candidates, create job postings, manage evaluations
Submit resume, view application status, update profile
View candidate pool, provide feedback, request specific evaluations
Limited view access for integrated systems, read-only operations
Rate limiting, validation, and attack prevention
Comprehensive rate limiting protects against brute force attacks, API abuse, and DDoS attempts.
Towards independent security verification
We are actively implementing SOC-2 Type I controls to provide independent verification of our security practices and controls effectiveness.
Implementing SOC-2 Type I controls
SOC-2 Type I Certification: Q4 2026
SOC-2 Type II certification planned for 2027 (demonstrating sustained control effectiveness)
SOC-2 certification by a qualified independent auditor will provide customers with documented assurance that our security, availability, processing integrity, confidentiality, and privacy controls meet industry standards.
Report security vulnerabilities responsibly
We take security seriously and appreciate responsible vulnerability disclosures. If you discover a security vulnerability in CVPRO, please report it to our security team.
security@talpro.in
Email your detailed security concern with steps to reproduce. Do not publicly disclose the vulnerability until we have had time to address it.
For more details on our vulnerability disclosure policy, response times, and recognition program, visit:
/.well-known/security.txtWe are committed to responding to security reports within 48 hours and working with researchers to resolve issues responsibly.
Contact us with any security, compliance, or data protection questions.
security@cvpro.inThis security information is current as of March 2026. CVPRO continuously updates its security practices to address emerging threats and maintain the highest standards of data protection.