Trust & Security

How we handle what you share.

Executive search runs on trust. This page describes the controls actually enabled on sercxi.io today — authentication, hosting, subprocessors, retention, privacy requests and accessibility — and points to the authoritative legal documents. Maintained by Sercxi B.V.

This is a factual description of app-visible controls, not an independent certification or audit report. Where a claim requires evidence (SOC 2, ISO 27001, penetration test reports), we will state so explicitly or leave it out.

Security controls

  • Data Encryption

    TLS 1.3 in transit · AES-256 at rest (managed Postgres and object storage).

  • Access Controls

    Partner-only operator access · role-gated via SECURITY DEFINER · RLS on every user-facing table.

  • Cross-Border Compliance

    GDPR (EU/NL) · PDPA (Singapore) · PDPL (UAE/KSA) · APPI (Japan) · PIPL (China outbound).

Authentication & Access

Role-scoped, server-validated

Sercxi's operator surfaces (framework downloads, diagnostic intake, admin views) are gated by a role table stored server-side, checked by a SECURITY DEFINER function on every request. Roles are never derived from client storage.

Row-Level Security is enforced on every user-facing table in the database; the service role is used only inside audited edge functions, never exposed to the browser.

Operator Security

Proton Business Suite for partner communications

Partner email runs on Proton Mail Business with end-to-end and zero-access encryption on a Sercxi custom domain. Every partner account is protected by two-factor authentication (TOTP or hardware key); shared inboxes are prohibited.

Partner devices reach client-sensitive systems over Proton VPN with always-on and kill-switch enabled. Credentials and shared secrets live in Proton Pass; sensitive documents at rest with partners live in Proton Drive (client-side encrypted). This is an operator control layered above the platform encryption applied to the sercxi.io database and object storage.

Data in Transit & At Rest

TLS end-to-end; managed database encryption

All traffic to sercxi.io and to our backend endpoints is served over HTTPS (TLS 1.2+). The underlying managed Postgres database and object storage encrypt data at rest by the platform provider.

Private artifacts (frameworks, gated PDFs) live in a non-public storage bucket and are served only via short-lived, function-issued URLs after email verification.

Candidate & Client Data

Written consent before any CV moves

We do not represent candidates to unnamed clients. No professional data or CV is shared without explicit, trackable written consent from the candidate.

Mandate intake, diagnostic responses and CRM sync payloads are transmitted server-side from validated edge functions — the browser never sees or stores client-side API keys.

Candidate materials exchanged with partners travel over Proton Mail (end-to-end encrypted between Proton counterparties, TLS with zero-access encryption otherwise) and, where retained by a partner, are stored in Proton Drive with retention aligned to the Candidate Privacy Notice.

Candidate Privacy Notice

Perimeter Hardening

Hardened HTTP headers, abuse throttling, HIBP passwords

Every response ships with HSTS (2-year, preload), a strict Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options, Referrer-Policy, Cross-Origin-Opener-Policy, and a locked-down Permissions-Policy. Framing, plugin embeds, and mixed content are blocked at the browser.

Public write endpoints (briefing intake, corridor-book generation, signal detection) are rate-limited per-IP and per-email in a shared database bucket that survives function restarts. Auth passwords are checked against the Have I Been Pwned database at sign-up and change.

Full security posture

Website Analytics

Cookieless, no cross-site profiling

We use Umami for aggregate analytics — no cookies, no persistent visitor IDs, no cross-site tracking. There is no consent banner because there is nothing to consent to.

Server logs are retained only for operational debugging and are not sold, shared or used for advertising.

Subprocessors

A short, named list — kept current

The full list of subprocessors that may process personal data on our behalf (hosting, database, email, CRM, analytics) is published and updated when it changes.

View subprocessors

Retention & Deletion

Purpose-bound retention windows

Candidate records are retained only for the durations described in the Candidate Privacy Notice and Master Terms. You can request access, correction or deletion of your data at any time.

Master Terms

Privacy Requests

Access, correction, deletion, portability

GDPR (EU/NL), UK GDPR, PDPA (Singapore), PDPL (UAE/KSA), APPI (Japan) and PIPL (China outbound) rights are honoured. Requests are actioned within statutory windows.

Email hello@sercxi.io with the subject line "Privacy Request" — a partner reviews every request personally.

Website Privacy Policy

Accessibility

EAA-aligned, WCAG 2.1 AA target

sercxi.io targets WCAG 2.1 Level AA and aligns with the European Accessibility Act (Directive 2019/882). The current status, known limitations and remediation roadmap are published in full.

Accessibility Statement

Vulnerability Reporting

Confidential intake for security researchers

If you believe you have discovered a security issue affecting sercxi.io or our backend endpoints, email hello@sercxi.io with the subject line "Security Report". Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.

We commit to acknowledging good-faith reports within five working days.

What we do not claim

Honest boundaries

We do not currently hold SOC 2, ISO 27001 or PCI-DSS certifications, and we do not represent that we do. We do not run continuous third-party penetration testing.

Where those controls are relevant to your procurement process, we are happy to discuss the underlying platform's compliance posture and provide an NDA-scoped questionnaire on request.