HiringCoach.ai

Physical security

Last reviewed 2026-05-17

<h2>Scope</h2> <p>HiringCoachAI is <strong>fully remote</strong>; we operate no first-party data centers, offices, or on-premises infrastructure. Physical security therefore focuses on <strong>personnel endpoints</strong> (laptops, mobile devices, authenticators) and our <strong>upstream providers</strong>.</p> <h2>Hardware supply-chain scope</h2> <p>HiringCoachAI is a cloud-hosted SaaS product. We do not manufacture, sell, lease, ship, or manage customer hardware, telecommunications equipment, physical appliances, embedded devices, or export-controlled computing devices. Institutions do not install HiringCoachAI hardware or agents.</p> <p>Personnel laptops, mobile devices, and authenticators are treated as endpoints rather than product hardware. Their hardening, loss/theft, and disposal requirements are documented below and in <a href="/trust/docs/acceptable-use">acceptable use</a>. Production cloud hardware supply-chain controls are managed by our infrastructure providers under their own audited programs.</p> <h2>Upstream physical security</h2> <p>All production data resides in Google Cloud Platform and Vercel. Google Cloud data centers are audited against ISO 27001/17/18/701, SOC 1/2/3, Payment Card Industry Data Security Standard (PCI DSS), HIPAA, and FedRAMP High. Vercel is SOC 2 Type II attested. We rely on these providers&#39; published physical controls and incorporate them by reference; cert links are maintained on <code>hiringcoach.ai/trust</code>.</p> <h2>Personnel endpoints</h2> <p>All personnel (employees, contractors, interns) comply with:</p> <h3>Device hardening</h3> <ul><li>Full-disk encryption <strong>mandatory</strong>: FileVault (macOS), BitLocker (Windows), LUKS (Linux). Verified at onboarding.</li><li>Automatic screen lock ≤ 10 minutes of idle.</li><li>Login password + biometric (Touch ID / Windows Hello / equivalent).</li><li>OS auto-updates enabled; security patches applied within 14 days of release as the operational target. Patches that cannot be applied within the target window — for example, because the vendor patch breaks tooling required for the work — are handled as a time-bound exception under the patch management exception process.</li><li>Browser auto-updates enabled.</li><li>Reputable anti-malware active (Defender on Windows; XProtect + Gatekeeper on macOS; clamav or similar on Linux).</li></ul> <h3>Mobile device hardening (if used for work)</h3> <ul><li>Device PIN ≥ 6 digits or biometric.</li><li>Find-my-device enabled.</li><li>Work email / 2FA apps (Google Authenticator, 1Password, Authy) pinned behind device unlock.</li></ul> <h3>Physical handling</h3> <ul><li>Devices not left unattended in public spaces (cafes, co-working spaces).</li><li>Screen privacy filter recommended in shared spaces.</li><li>No unknown / untrusted USB drives.</li><li>Devices locked or powered off when traveling.</li></ul> <h3>Authenticators</h3> <ul><li>Hardware keys (YubiKey) encouraged for the Security Officer and admins; stored physically secured when not in use.</li><li>TOTP apps (1Password, Authy, Google Authenticator) protected behind device unlock + app-level PIN where available.</li></ul> <h2>Loss / theft procedure</h2> <p>If a work device or hardware authenticator is lost or stolen:</p> <p>1. <strong>Within 1 hour of discovery:</strong> notify the Security Officer. 2. Remote wipe: Find-my (Apple/Google), Windows &quot;Remote Lock&quot;, or Google Workspace MDM. 3. Revoke all sessions from the affected device (audit log → force sign-out; rotate OAuth refresh tokens for the user). 4. Rotate any credential the device may have cached. 5. File a police report if theft; include report number in the incident post-mortem. 6. Evaluate whether personal data was accessible on the device: if yes, treat as potential breach per <a href="/trust/docs/breach-notification">breach notification</a>.</p> <h2>Visitor / office access</h2> <p>N/A: no offices.</p> <h2>Disposal of media</h2> <ul><li>Before disposing of any device that held HiringCoachAI data or credentials: full secure wipe (cryptographic erase on encrypted drives is acceptable) or physical destruction.</li><li>Disposal is logged in the restricted device-disposal evidence set with date, device type, and method.</li><li>Cloud-stored data disposal is Google/Vercel&#39;s responsibility per their certifications.</li></ul> <h2>MDM</h2> <p>Endpoint device hygiene is enforced by acknowledgement at onboarding and verified at each internal audit.</p> <h2>Related</h2> <ul><li><a href="/trust/docs/acceptable-use">acceptable use</a></li><li><a href="/trust/docs/background-checks">background checks</a></li><li><a href="/trust/docs/access-control-policy#provisioning--deprovisioning">access control policy — provisioning and deprovisioning</a></li></ul>

← Back to the trust center

showUpgradeModal: false, modalType: migration, planName: