Candidate and client information
Access should be limited to personnel and authorized providers who require the information for recruitment, onboarding, verification, customer support or another defined business purpose.
Verification integrations
Protected API keys or provider credentials must remain server-side or otherwise protected and must not be exposed on public web pages or to unauthorized users.
Incident reporting
Suspected unauthorized access, account misuse or inappropriate disclosure should be reported promptly through our compliance or support contact.