Trust Center
Trust, security and responsible AI
How CanadaBridge AI protects the people and companies on the platform. This page is maintained by the Hyprocom team and describes our current practices — it is not an independent audit or certification.
Last updated 2026-08-04
System status
- A public health probe reports application and database availability in real time.
- Planned maintenance is announced in-product before it starts.
- The platform runs on managed Postgres with automated backups and point-in-time recovery.
Security
- All traffic is served over HTTPS with modern TLS; credentials are never stored in the app.
- Authentication supports email, magic links and Google, Apple and Microsoft sign-in.
- Role-based access control governs every screen, with permissions resolved per role.
- Row-level security is enforced in the database itself, so access rules cannot be bypassed by the client.
Data protection
- Documents (résumés, certificates, portfolios) are stored in private buckets and served through short-lived signed links.
- Data is encrypted in transit and at rest by the hosting platform.
- Sensitive actions are written to an append-only audit trail.
- Deletion is soft-deleted first, then purged on request.
Privacy
- We process personal data under PIPEDA and, for applicants in the EU, the GDPR.
- Candidates control profile visibility and can export or delete their data.
- We do not sell personal data, and we do not use candidate data to train third-party models.
Responsible AI
- AI features assist people; they never make an automated hiring decision on their own.
- Match scores are explainable — each score is accompanied by the factors behind it.
- Prompts exclude protected characteristics such as age, gender, religion and national origin from scoring.
- Every AI run is logged so an output can be traced back to its inputs and model.
Compliance
- Canadian employment context: LMIA and Express Entry fields are structured, not free text.
- Legal terms, acceptable use and a Data Processing Addendum are published and versioned.
- Sub-processors are limited to our hosting, database and AI infrastructure providers.
Incident history
- No security incidents have been recorded to date.
- Confirmed incidents affecting personal data are reported to affected users and regulators as required by law.
- Post-incident summaries are published on this page.
Accessibility
- We target WCAG 2.1 AA: semantic landmarks, keyboard navigation and visible focus states.
- The interface ships in English, French and Arabic with full right-to-left support.
- Dark and light themes both meet contrast requirements.
Contact the security team
Report a vulnerability or a suspected data issue to security@jobs.hyprocom.com. Privacy requests go to privacy@jobs.hyprocom.com. We acknowledge reports within two business days and ask that you give us a reasonable window to remediate before public disclosure.
Full legal terms are available in the legal centre.