Security Policy

Last updated: February 11, 2026

1. Purpose

This Security Policy describes the administrative, technical, and organizational measures implemented by Aperture Labs Inc. ("Aperture," "we," "us," or "our") to protect the confidentiality, integrity, and availability of data processed through the Aperture platform and related services (the "Services").

Aperture is committed to maintaining reasonable and appropriate safeguards designed to protect personal information and interview data processed through the Services.

2. Infrastructure and Hosting

Aperture's infrastructure is hosted on managed server environments operated by third-party hosting providers. Application services and databases are deployed in controlled hosting environments designed to support secure operation of the Services.

Key infrastructure practices include:

  • Use of secure hosting environments for application and database infrastructure;
  • Network-level protections provided by infrastructure providers;
  • Use of content delivery and network protection services to help mitigate malicious traffic and improve availability;
  • Separation of application services and backup environments where feasible.

Interview recordings and application data are stored on dedicated server environments operated by Aperture.

3. Data Transmission and Encryption

Aperture implements encryption in transit to protect data during transmission.

Security measures include:

  • HTTPS/TLS encryption enforced for all external communications;
  • Encrypted connections used when transmitting data between systems and third-party services;
  • Secure transmission of audio and interview-related data to processing systems.

Database and backup storage employ encryption mechanisms designed to reduce unauthorized access risks.

While reasonable safeguards are implemented, no transmission or storage system can be guaranteed to be completely secure.

4. Access Control

Access to production systems and data is restricted to authorized personnel based on operational requirements.

Security practices include:

  • Role-based access controls (RBAC);
  • Access limited to founders, authorized engineers, contractors, and authorized business users as required for service operation;
  • Multi-factor authentication (MFA) required for administrative access;
  • Periodic review of access permissions where applicable.

Users are responsible for maintaining the confidentiality of their credentials.

5. AI Processing and Third-Party Processing

Certain features of the Services require processing of interview data by third-party AI systems.

Security practices include:

  • Transmission of data to processing services over encrypted connections;
  • Limitation of shared data to information necessary to perform requested processing functions.

Aperture does not control how third-party providers internally store or process data beyond contractual or technical safeguards implemented where applicable. Users acknowledge that third-party processing may occur outside Aperture-controlled infrastructure.

6. Logging, Monitoring, and Detection

Aperture maintains operational monitoring measures intended to support platform security and reliability, including:

  • System and access logging;
  • Error monitoring;
  • Security monitoring mechanisms;
  • Automated alerts for abnormal system behavior where applicable.

These measures are intended to assist in identifying and responding to potential security events.

7. Backup and Disaster Recovery

Aperture performs automated backups of critical data on a regular basis.

Current practices include:

  • Automated daily backups;
  • Storage of backups on separate servers within the same geographic region;
  • Maintenance of recovery procedures appropriate to the current operational stage of the Services.

Disaster recovery processes are maintained on a reasonable-efforts basis and may evolve as the Services mature.

8. Incident Response

Aperture maintains internal processes intended to respond to security incidents in a timely manner.

In the event of a confirmed security incident, Aperture will take reasonable steps to:

  • Investigate the incident;
  • Contain and mitigate impact;
  • Restore service integrity where possible;
  • Notify affected parties where required by applicable law.

Response timelines may vary depending on the nature and scope of the incident.

9. Employee and Operational Security

Aperture requires team members with system access to follow reasonable security practices, including:

  • Use of secure devices;
  • Credential protection and password management practices;
  • Restriction on unauthorized sharing of access credentials;
  • Limiting data access to operational needs.

10. Vulnerability Management

Aperture maintains practices intended to reduce security risks, including:

  • Security scanning and monitoring of systems where applicable;
  • Dependency monitoring;
  • Application of security updates and patches on a reasonable schedule.

Security improvements are implemented continuously as part of ongoing platform development.

11. Compliance and Certifications

As of the date of this policy, Aperture is not certified under SOC 2, ISO 27001, HIPAA, or FedRAMP frameworks.

This policy describes operational practices and does not constitute a certification or guarantee of compliance with any specific security standard.

12. Shared Responsibility

Security is a shared responsibility between Aperture and users of the Services.

Business users are responsible for:

  • Maintaining secure access to their accounts;
  • Ensuring lawful collection and submission of candidate data;
  • Managing access permissions within their organization;
  • Complying with applicable employment and data protection laws.

13. Changes to This Policy

Aperture may update this Security Policy from time to time to reflect operational or technological changes. Updates will be indicated by the revised "Last Updated" date.

14. Contact

For security-related inquiries, please contact [email protected]