Infrastructure and Operations
Hosting
Kira Talent hosts its core infrastructure with AWS. All services and servers are set up in a redundant fashion using AWS best practices. Additionally Kira uses AWS’s technical consultants to help review its security and configuration practices multiple times per year.
Kira’s servers are not publicly accessible. They sit behind secure proxies and firewalls and are only accessible to a small group of approved and experienced engineering team members.
AWS maintains SOC 2 and ISO 27001 certifications.
Application Monitoring & Notifications
Kira Talent uses several tools and services to monitor platform availability and infrastructure health. A subset of employees are on a revolving on-call schedule and are automatically contacted in case of alerts, downtime and emergencies. We also employ 2 levels of fallback on alerts.
Operational Security
Our cloud hosting providers provide proactive, and immediate patching of critical updates; packages are obtained from trusted sources only. Vulnerability is routinely tested according to their SOC 2 compliance.
The Kira Talent platform is routinely checked against known vulnerabilities and patched based on the severity and urgency of the threat.
Encryption and System Security
Encryption In Transit
All data transmissions are encrypted and authenticated using a strong protocol (TLS 1.2), a strong key exchange (ECDHE_RSA with P-256), and a strong cipher (AES_256_GCM).
Encryption At Rest
Kira’s database is provided by Amazon Web Service’s Aurora Relational Database service. The Aurora service has been configured to use high grade encryption at rest,
Amazon RDS encrypted DB clusters use the industry standard AES-256 encryption algorithm to encrypt your data on the server that hosts your Amazon RDS DB clusters. Once your data is encrypted, Amazon RDS handles authentication of access and decryption of your data transparently with a minimal impact on performance. - Encrypting Amazon RDS Resources
Principle of Least Privilege
Kira follows the principle of least privilege from both an application and infrastructure point of view. Data access on Kira’s platform is permitted only within an organization’s context and is restricted by the role of a user (along with explicit permissions added if needed).
At the infrastructure level, Kira uses Security Groups to determine allowable ingress and egress traffic. Kira uses a “deny all, allow some” approach to opening ports for traffic.
2-Factor Authentication
Kira launched a 2FA feature in Q2 2019 allowing clients to require that all users within their organizational context have a second authenticator factor setup.
Kira internally also uses 2FA with all 3rd party tools and systems which support it.
Penetration Testing
Kira undergoes a full penetration test at least once a year. The results of the last penetration test executed against Kira’s platform in August/September 2022 showed no significant red flags or high risk issues identified.
Data Processing
Kira will not use data containing personal information for any purposes other than those identified in the Terms of Service and Privacy Policy. Kira maintains the minimum amount of data required to perform its obligations under the Terms of Service, Privacy Policy and any applicable agreements.
From time-to-time, Kira may anonymize its data records for the purposes of facilitating the developments of new or enhanced services. Any and all data identified in the Data Inventory and Processing Documentation records must be removed either via automated or manual means Before any processing of this data can be performed.
Kira’s Data Protection Officer must confirm that the data has been properly anonymized and will log the anonymization activities in the Security and Compliance Team folder.
GDPR Compliance
Kira is GDPR-compliant. All of the sub-processors that we use also need to abide by the regulations outlined in the GDPR and are required to have a signed Data Protection Agreement (DPA) with Kira in order for them to be used.
Kira has processes in place to handle “Right to erasure” requests and works with its clients and their applicants on a per request basis to handle anything data privacy related.
Uptime and Disaster Prevention
- 99.9% uptime service level commitment
- 24x7x365 Network Operations Centre (NOC)
- On a nightly basis, customer databases are backed up in full, from the active failover server, ensuring backup processes do not disrupt access to customer data. Backups are shipped off-site over a dedicated fiber link to another secure Canadian location, ensuring that even in the event of a critical disaster, customer data is secure.
Operational Best Practices
- Fully guarded premises and physical access management that are economically unfeasible with typical in-house, on-premise deployments. Dedicated around-the-clock availability and security monitoring provide added layers of assurance.
- Highly Restrictive Physical Access
- Audited Access Controls
Outside of core data operations, we designed our physical office to eliminate any central on-premise servers, ensuring employees and guests have no direct access to customer data. When requesting support, either at the time of request submission or during the course of interaction with our team, customers have the opportunity to grant any necessary access rights.
SOC 2 Type II
SOC 2 Type II certification is a third-party audit that’s part of the American Institute of CPA’s (AICPA) Service Organization Control reporting platform and a necessity for any cloud SaaS business. To achieve SOC 2 compliance, companies undergo a rigorous audit of the security policies and controls it has in place to protect our customers’ data. Kira Talent's SOC 2 Type II compliance certification confirms that Kira has written – and operates our business – based on a set of comprehensive information security policies and procedures.
IASME Cyber Essentials Certified
Kira maintains a current IASME Cyber Essentials Certificate of Assurance indicating compliance with requirements of the Cyber Essentials Framework for the entire organization. This Certificate certifies that the organization was assessed as meeting the Cyber Essentials implementation profile and thus that, at the time of testing, the organizations ICT defenses were assessed as satisfactory against commodity based cyber attack.
You can request a copy of our IASME Certification through your Customer Success Manager.
Additional Security
AWS and Subprocessor datacenters are locked and guarded, and can only be accessed by authorized personnel. Monitored closed circuit television systems and onsite security teams vigilantly protect our datacenter around the clock, while military-grade pass card access and biometric finger scan units provide even further security.
Regulated Climate Control
Our heating, ventilation, and air-conditioning (HVAC) systems have full particle filtering and humidity control. The climate within each of our datacenters is maintained according to ASHRAE Guidelines. This ensures your mission-critical dedicated server and hardware is functioning at its best.
Redundant Power
Unlike some providers, we don’t rely solely on the local power grid to guarantee around-the-clock power. Onsite diesel-powered generators and uninterruptible power systems (UPS) deliver redundant power if a critical incident occurs, so that all operations are uninterrupted and your dedicated servers remain online. We regularly test our infrastructure to make sure it performs as designed in the event of an emergency. And we back it all up with our 99.9% Uptime SLA.
Fire Suppression
Pre-action dry pipe sprinkler system with clean agent fire extinguishers.
24×7 Support
The Network Operations Center (NOC) staff monitors the network 24x7x365, while our network engineers and facility staff are available at any time in the event of an emergency. You also have around-the-clock access to online support and resources.
FAQ
Do you protect the video interview screening system from unrestricted access by installing a firewall or router?
Yes, our system’s servers are protected from unrestricted access – only our internal employees have VPN access to them, and access is monitored.
Do you keep records of access to personal information?
Yes, we have access logs which record IP Addresses and URLs accessed, which are stored for 30 days.
Do you protect access records from divulgation, loss or damage for a certain period? If you do, how long do you keep the records?
Yes, our databases are backed up on a nightly basis. Once a night, we take a snapshot of our VMs, backup the data, encrypt them with strong GPG encryption, then ship them to our offsite facility. We retain 30 days worth of backups at any given time.
Have you implemented an antivirus software?
Yes. All endpoints are required to maintain virus protection at all times. All platform data is stored on Linux based systems which are managed and monitored for security issues and regularly patched and updated.
Do you apply a security patch to the operation system, application and etc.?
Yes, we update our servers, operating systems, libraries, applications, and VMs with security patches when released.
Do you implement any measures, such as encrypted communication or https, to prevent from being stolen data during transmission? If you do, please specify.
Yes, we use HTTPs and TLS 1.2 to encrypt communication in transit.
Do you monitor the usage of the video interview screening system?
Yes, we monitor usage details – for example, login access, reviewer information (when is someone reviewing, who is reviewing applicants), applicants taking video interviews, videos being recorded and streamed to our servers.
Do you monitor the access records to personal information?
Yes.
Do you test vulnerability regularly? If you do, how often?
Yes, all our machines are monitored daily using an industry leading 3rd party security testing firm. We also conduct penetration testing annually.
When you make any changes to the video interview screening system, do you check if the change is not destructive to the security of the system?
Yes.
Do you backup personal information regularly? If you do, how often?
Our databases are backed up on a nightly basis. Once a night, we take a snapshot of our VMs, backup the data, encrypt them with strong GPG encryption, then ship them to our offsite facility. We retain 30 days worth of backups at any given time.
Do you confirm the normality of the backup data?
Yes.
How long do you keep the backup data?
Backup data is kept for 30 days.
Do you conduct vulnerability testing, and to what extent? What is done with vulnerability findings? Are clients notified of risks to their accounts and data?
We have a policy that covers our vulnerability monitoring and testing which is done continuously. We also conduct manually checks by looking at all aspects of our source code that can be vulnerable (e.g. SQL injection, cross-site scripting, exposing sensitive data, etc), as well as using 3rd-parties services to conduct scans.
Vulnerability findings are assessed and all that are found to be at critical or high-risk are mitigated as soon as possible (30 days). Mitigated findings are re-tested to confirm they have been solved.
We have a policy in-place that when a client-impacting vulnerable is found, they are notified of the risks to their accounts and data.
Will our data be encrypted at rest? What algorithm?
Kira encrypts data at rest using AES 256 bit encryption algorithm.
For encrypting end-user passwords, we use the PBKDF2 algorithm with a SHA256 hash, a password stretching mechanism recommended by the National Institute of Standards and Technology.
Will our data be encrypted in transit, including between servers? What algorithm?
All data requests to and from our product in transit happen over HTTPS and are encrypted TLS1.2. We also sign requests using the client secret that we provide to you (using the shared secret as key) and encrypt the payload using SHA256.
Do you have endpoint protection in place?
All devices that access Kira data are required to have endpoint management and protection software installed and running at all times. This software also ensures all data stored on those remote machines is encrypted at all times and can be wiped remotely. Devices are forced to use strong password protection and rotation policies as well as screen locking and timeout limits under 5 minutes.