Security
Security Overview
MarqHireAI is structured to support business hiring workflows, with access controls, audit surfaces, and third-party provider boundaries that can be configured for production use.
Access Control
The application supports authenticated workspaces, route protection, team membership roles, and owner or admin controls for billing, ATS destinations, and member management.
Operational Audit Surfaces
Billing updates, inbound resume events, and ATS export events are designed to be tracked through the database-backed schema used by the application. That provides a foundation for internal workflow review and troubleshooting.
Provider Boundaries
Production security depends on the services you configure around the app, including the database, Razorpay, SendGrid, and any ATS webhook destinations. Review each provider's settings, credentials, retention rules, and incident response posture before launch.
Important Note
MarqHireAI does not currently ship with a formal SOC 2 program, SSO, or a customer-facing compliance package. Those are roadmap items and should not be represented as complete until they are separately implemented and reviewed.