Overview
  • Dashboard
  • PeopleSoft integration
Recruiting
  • Recruiter CRM
  • Candidate matching
  • Application workflow
  • Veterans' Preference
  • Job distribution
Compliance
  • Reporting & audit
  • Security & trust
Compliance/Security & trust
Security, Data Residency & Accessibility

Every person who can touch North Dakota production data is based in the United States and background-checked. We state exactly what is in place today — and what is in progress — and never claim a certification we don't hold.

Data Residency & Access
US-only
US-only AWS regions
All North Dakota production data stays in US AWS regions — never replicated offshore.
US-based staff only
Every person who can access ND production data is based in the United States and background-checked.
Least-privilege RBAC
Role-based access control; production access is logged and reviewed quarterly.
Per-tenant isolation
North Dakota's data is logically isolated with per-tenant encryption keys.
Encryption & Security
at rest + in transit
Encryption at rest
AES-256 with AWS KMS customer-managed keys.
Encryption in transit
TLS 1.3 on every connection, including the PeopleSoft Integration Broker.
Field-level encryption
SSN, date of birth, and veteran status encrypted at the field level.
7-year audit retention
Every API call and data access logged and retained 7 years.
Compliance & Certifications
SOC 2 Type II
In progress
Audit underway — target Q3 2026. Controls operate today; the report is shared with ND on completion.
NIST 800-53 aligned controls
Active
Security program mapped to the NIST 800-53 moderate baseline.
Independent penetration test
Active
Annual third-party penetration test; findings remediated to closure.
Quarterly bias audits
Active
Independent fairness testing every quarter, results shared with ND HRMS.
Accessibility & Responsible AI
WCAG + bias audits
WCAG 2.2 AA · VPAT
Candidate and recruiter interfaces built and tested to WCAG 2.2 AA. VPAT available on request.
Section 508
Conforms to Section 508 for public-sector accessibility.
Language access (Title VI)
Multilingual candidate experience for limited-English-proficiency applicants.
Keyboard & screen-reader
Full keyboard navigation and screen-reader support, including the mobile apply flow.
NIST AI RMF · human review
Matching aligned to the NIST AI Risk Management Framework; protected attributes excluded, every score explainable, and candidates may request human review.
No candidate is ever screened out by an algorithm alone. Protected attributes are excluded from matching, every score is explainable, and a human can override any recommendation in one click.