loading ...
loading ...
Last updated: February 11, 2026
This Security Policy describes the administrative, technical, and organizational measures implemented by Aperture ("Aperture," "we," "us," or "our") to protect the confidentiality, integrity, and availability of data processed through the Aperture platform and related services (the "Services").
Aperture is committed to maintaining reasonable and appropriate safeguards designed to protect personal information and interview data processed through the Services.
Aperture's infrastructure is hosted on managed server environments operated by third-party hosting providers. Application services and databases are deployed in controlled hosting environments designed to support secure operation of the Services.
Key infrastructure practices include:
Interview recordings and application data are stored on dedicated server environments operated by Aperture.
Aperture implements encryption in transit to protect data during transmission.
Security measures include:
Database and backup storage employ encryption mechanisms designed to reduce unauthorized access risks.
While reasonable safeguards are implemented, no transmission or storage system can be guaranteed to be completely secure.
Access to production systems and data is restricted to authorized personnel based on operational requirements.
Security practices include:
Users are responsible for maintaining the confidentiality of their credentials.
Certain features of the Services require processing of interview data by third-party AI systems.
Security practices include:
Aperture does not control how third-party providers internally store or process data beyond contractual or technical safeguards implemented where applicable. Users acknowledge that third-party processing may occur outside Aperture-controlled infrastructure.
Aperture maintains operational monitoring measures intended to support platform security and reliability, including:
These measures are intended to assist in identifying and responding to potential security events.
Aperture performs automated backups of critical data on a regular basis.
Current practices include:
Disaster recovery processes are maintained on a reasonable-efforts basis and may evolve as the Services mature.
Aperture maintains internal processes intended to respond to security incidents in a timely manner.
In the event of a confirmed security incident, Aperture will take reasonable steps to:
Response timelines may vary depending on the nature and scope of the incident.
Aperture requires team members with system access to follow reasonable security practices, including:
Aperture maintains practices intended to reduce security risks, including:
Security improvements are implemented continuously as part of ongoing platform development.
As of the date of this policy, Aperture is not certified under SOC 2, ISO 27001, HIPAA, or FedRAMP frameworks.
This policy describes operational practices and does not constitute a certification or guarantee of compliance with any specific security standard.
Aperture may update this Security Policy from time to time to reflect operational or technological changes. Updates will be indicated by the revised "Last Updated" date.
For security-related inquiries, please contact support@aperturehq.org