← Back to AI HR PilotSecurity
Last updated: July 6, 2026
HR data is among the most sensitive data a company holds. This page states exactly what we do to protect it, what our infrastructure providers certify, and what we have not certified yet. No badge on this site claims a certification we do not hold.
What we do today
- Encryption: all traffic is encrypted in transit (TLS); data is encrypted at rest by our database and storage providers.
- Tenant isolation: every database query is scoped to your organization's identifier, which is derived server-side from your authenticated session and never accepted from the client.
- Role-based access: four permission levels (employee, HR staff, legal, HR admin) enforced on the server for every API route.
- Audit logging: questions, answers, escalations and admin actions are logged and reviewable by your admins.
- Sensitive-topic escalation: harassment, discrimination, ADA, FMLA and similar topics are flagged and routed to humans rather than answered casually by AI.
- No training on your data: your documents and conversations are used only to answer your organization's questions.
- Webhook and payment integrity: Stripe and authentication webhooks are cryptographically signature-verified.
Our infrastructure providers
The Service runs on providers that maintain their own security certifications: Vercel (hosting and storage), Neon (database), Clerk (authentication, SOC 2 Type II certified) and Stripe (payments, PCI DSS Level 1). Their certifications apply to their infrastructure, not to AI HR Pilot as a product, and we say so plainly.
What we have not done yet
- SOC 2: AI HR Pilot has not completed its own SOC 2 audit. It is on our roadmap, prioritized by customer demand.
- Penetration test: no third-party pentest has been completed yet.
- SSO/SAML: enterprise single sign-on is not yet available (Google and Microsoft OAuth are supported via Clerk).
Data processing and DPAs
Our data handling is described in the Privacy Policy, including the current subprocessor list. If your procurement process requires a signed Data Processing Agreement, contact us and we will execute one as part of onboarding.
Reporting a vulnerability
If you believe you have found a security issue, email support@aihrpilot.com with "SECURITY" in the subject line. We will acknowledge within 2 business days and keep you informed through resolution.