Trust center
Documents stay with SNAP. We encrypt the rest.
SNAP holds the ID and the proofing photo. We encrypt the personal data we keep, sign every TrustMark, and let only verified recruiters open one.
Documents and selfies stay with SNAP.
Contact details are encrypted. TrustMarks are signed.
Only recruiters at verified companies can open a TrustMark.
Encryption and signing
How we lock the data we hold.
Candidate email and phone, company tax IDs, recruiter invite emails, and authenticator secrets are encrypted at rest. Every TrustMark carries two signatures: a signed verification token, and a standard digital signature on the PDF itself.
If signing is not available, we do not issue a mark. We never hand out an unsigned file. Operations staff actions are written to an audit log.
- Checked on every scan
- Opening a TrustMark re-checks the token signature and the file details behind it.
- Expiry
- A TrustMark expires after a year and stops verifying.
Sign-in
Passkeys, and a step-up for anything sensitive.
Accounts sign in with a passkey, or with Google or Apple. We check passkeys against the FIDO Alliance metadata service. Résumé changes and TrustMarks ask for a stronger sign-in: a passkey or an authenticator code. Recovery codes cover a lost device.
- Recruiter access
- Recruiters join by invite, and each invite only works for the email it was sent to.
- Organization checks
- A company proves its domain with a DNS record, and its founder completes SNAP, before anyone can be invited.
Identity privacy
SNAP holds the documents. Recruiters see verified.
SNAP holds the government ID and the photo from that check. SnapRecruit stores the result: whether it passed, and when.
A recruiter can act on that. They cannot download a passport or a selfie from us.
Privacy law
GDPR, CCPA, and PIPEDA — what we do.
The identity data we store is personal data. GDPR, CCPA, and PIPEDA apply to it. We keep only what the product needs and honor access and erasure requests.
A data processing agreement is available for employers who need one. Email security@certipath.com with the org and the jurisdictions you hire in.
- Rights we honor
- Access and erasure, with a human path for account-level privacy requests.
- What we ask of you
- Do not send us data this product is not built to hold. Identity results and résumés belong here. Health records do not.
Partners
Who processes data with us.
Identity proofing: SNAP / CertiPath. Optional sign-in: Google and Apple, only when the candidate chooses them. Passkey checks use the FIDO Alliance metadata service, which we download; it receives nothing about you.
Contact
Report a vulnerability. Ask for a DPA.
Email security@certipath.com. Use that address for suspected vulnerabilities, privacy requests, and commercial security questionnaires. Do not file a public GitHub issue with exploit details.
We will acknowledge a vulnerability report and work the fix. For a DPA or an employer security review, send the org name and the frameworks you need us to map against the practices on this page.
Questions
What people ask.
- Do employers see identity documents?
- No. SNAP holds the ID and proofing photo. Recruiters see that the person is verified.
- Who can open a TrustMark?
- Signed-in recruiters at verified companies. Anyone else sees nothing.
- How do we get a DPA?
- Email security@certipath.com with the org name and the jurisdictions you hire in.
- What if SNAP is still in progress?
- There is no TrustMark yet. An unfinished check is not a failed one.
Questions about your org’s data?
Request a DPA or send a privacy request. We answer from what the product does.