Security and responsible use

What we do, and what we refuse to do.

Stated plainly, including the parts that are not finished.

Pre-launch legal notice

The assessment workflow, client contract, candidate notice and consent language, FCRA and employment-law applicability, and jurisdictional requirements must be reviewed and approved by qualified counsel before production client or candidate data is accepted. This page and this application are not legal advice and must not be relied on as such.

What we do not claim

KeenSix makes no claim of SOC 2, HIPAA, GDPR or FCRA compliance, no encryption certification, and no malware scanning. Any such claim will appear only after it has been actually configured and independently verified.

Tenant isolation at the database

Every record is scoped to an organization and enforced with database row-level security, not client-side filtering. A client user cannot read another company's organizations, users, cases, candidates, files, messages, invoices or reports.

Private file storage

Uploaded materials live in a private, non-public store. Downloads are served through short-lived signed URLs to authorized users only. Uploads are validated for file type and size.

No malware scanning yet

Uploaded files are NOT scanned for malware today. Until that is configured and verified, do not upload files from untrusted sources.

Job-related information only

Intake collects role-related information. We do not solicit protected characteristics, and we ask clients not to supply them.

Prohibited inference

KeenSix does not perform facial-expression, emotion, voice-stress, biometric, personality, medical, disability, family, religious, political or deception inference. Ever.

No automated decision

No automated rejection, ranking or scoring of candidates is produced. Human approval by a senior KeenSix assessor is required before any report is released.

Candidate correction and audit trail

Candidates may submit corrections. Corrections append and version the record; original evidence and original wording are never overwritten. Consequential actions are written to an audit log.

Retention and deletion

Each engagement carries a configurable retention date. Clients and candidates may request deletion, subject to contractual and legal obligations.

Secrets stay server-side

Service credentials are never exposed to the browser. Privileged operations run server-side against authorization checks.

See launch readiness status