Security
This page is maintained by NANA OS to answer common security and privacy questions about the platform. It describes the controls currently in place; it is not a certification or an independent audit.
Agency-only access
Every record belongs to a single agency and is isolated at database level. Access rules are enforced by the database itself, so one agency can never read or change another agency's candidates, clients, vacancies, placements or documents.
Encrypted connections
All traffic between your browser and the platform is encrypted in transit, and data is encrypted at rest on managed cloud infrastructure.
Secure document storage
Candidate documents are stored in private storage that is not publicly reachable. Files are only ever opened through short-lived signed links generated for a signed-in member of the owning agency. Uploads are limited by size and file type.
Role-based permissions
Team access is granted by role — owner, administrator, recruiter, compliance and read-only — so people only see and change what their job requires. Destructive actions are restricted to owners.
Candidate consent recording
Candidates give explicit consent during registration. The consent version, method, policy link and timestamp are written to an append-only record that cannot be edited afterwards.
Audit logs
Changes to candidate records and documents are recorded with the actor, the action and the time, giving agencies an evidence trail for compliance reviews.
Backups
The platform runs on managed infrastructure with encrypted, regularly taken backups.
Shared responsibility
NANA OS secures the platform. Agencies remain responsible for who they invite, the accuracy and lawfulness of the data they store, and their own retention decisions. Candidates should raise data requests with the agency they registered with.
Independent testing
Independent penetration testing is planned. This page will be updated when it has been completed; until then we make no claim of external certification.
Reporting a vulnerability
Please report suspected vulnerabilities to security@nanaos.app with enough detail to reproduce the issue. See also our privacy policy.