01Our approach#
HackSprint runs timed assessments that decide who advances in a hiring process. That makes two things security critical: the integrity of a result, and the confidentiality of everything captured to establish it. We design for both, and we assume any signal we collect will eventually be read by a human who has to justify a decision with it.
02Hosting#
The platform runs on a major managed cloud provider. We do not operate our own data centres or physical hardware, so physical security, hardware lifecycle, and the provider’s own independent audits are inherited rather than reproduced by us. We can name the provider and share their current certifications under a diligence request.
03Encryption#
Data is encrypted in transit and at rest throughout the platform, using current industry-standard algorithms and our cloud provider’s managed key service. We review the configuration as standards move rather than pinning to a version.
04Workspace isolation#
Participant code executes in an isolated sandbox created for that session and destroyed when it ends. A sandbox has no route to another participant’s session, to our internal network, or to the grading service’s internals.
05Access control#
06Proctoring evidence#
Proctoring is the most sensitive thing we hold, so it is the most constrained.
07Identity data#
Where an event enables identity verification, we capture a baseline image at calibration and compare later activity against it to detect a mid-session swap.
08Data location#
We and our service providers operate in more than one country, so customer data may be processed outside the country an organization is based in. Regional processing is available for organizations that require it. Transfers out of the EEA, UK, or Switzerland rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where relevant, supported by a transfer risk assessment. Our data processing addendum and current service provider list are available on request, and the participant-facing detail is in the Privacy Policy.
09Availability and continuity#
Our current recovery objectives and uptime history are shared as part of a diligence review rather than published, so the figures you receive are the ones in force at the time you ask.
10Application security#
11Service providers#
Every provider that can touch personal data is reviewed before use and re-reviewed periodically, covering their independent audits, retention terms, and transfer mechanism. We hold a written processing agreement with each. Customers are told before a new provider starts handling their data, with time to object.
12Incident response#
13Diligence and documentation#
We would rather be exact with you than reassuring in public, so the specifics go in a diligence pack instead of on this page. On request we can provide our data processing addendum, our current service provider list, our transfer mechanism, the summary from our most recent independent penetration test, our present certification status and roadmap, and a completed copy of your own security questionnaire.
Request any of these through the contact form by selecting the security topic.