Trust

Security

GoMeasure measures people on evidence — so protecting that evidence is foundational. This is how we secure the data you and your people entrust to us.

Last updated: 17 September 2026

1. Our Approach

Security is treated as a design requirement, not an afterthought. We collect only the data we need to measure skills and produce verified proof, we limit who can access it, and we keep it encrypted and logically separated by organisation. Where a control is still maturing, we say so rather than overclaim — and we're happy to discuss specifics with your security team.

2. Encryption

All traffic to and from GoMeasure is served over HTTPS/TLS, so data is encrypted in transit between your browser and our services. Data stored in our databases and object storage is encrypted at rest using the encryption provided by our cloud infrastructure providers.

3. Infrastructure & Hosting

GoMeasure runs on reputable cloud infrastructure, primarily Amazon Web Services (AWS), with the marketing site delivered via Vercel. We rely on the physical, network and platform security of these providers, which maintain their own industry certifications and controls. Production data for Indian customers is hosted in an India region.

4. Access Control & Data Separation

Access to production systems and customer data is restricted to authorised team members on a least-privilege basis, and is protected by individual accounts and strong authentication.

GoMeasure is multi-tenant: each customer's data is scoped to their organisation at the application layer, so one organisation cannot see another's candidates, assessments, or results.

5. Assessment & Interview Integrity

Because our output is decision-grade proof, integrity is part of security. Our integrity layer (TrustOS) supports identity and monitoring signals during assessments and interviews, and scores are evidence-anchored so a result can be explained and defended. Integrity features are configurable per assessment.

6. How We Use Your Data

We do not sell or rent your data, and we do not use your candidates' or employees' data to train third-party AI models. Personal data is processed to deliver the service you have configured — measuring skills, generating reports, and producing verified proof — and in line with our Privacy Policy.

7. Sub-processors

We use a small set of trusted service providers to operate the platform — for example cloud hosting and databases (AWS), site delivery (Vercel), and transactional email (Resend). Each is engaged to provide a specific function and is expected to maintain appropriate security controls. A current list of sub-processors is available to customers on request.

8. Reporting a Vulnerability

We welcome responsible disclosure. If you believe you've found a security issue in any GoMeasure product or website, please email security@gomeasure.ai with the details and steps to reproduce. Please give us reasonable time to investigate and remediate before any public disclosure. We will acknowledge your report and keep you updated on our progress.

9. Compliance & Requests

For enterprise buyers, we can provide further detail on our security posture and discuss a Data Processing Agreement (DPA), data-residency needs and any security questionnaire as part of procurement. To start that conversation, contact our team at sales@gomeasure.ai.

10. Contact

Questions about security or a specific control?

Security & vulnerability reports: security@gomeasure.ai
Sales & commercial enquiries: sales@gomeasure.ai
Website: www.gomeasure.ai/contact

Evaluating GoMeasure for your organisation? Talk to our team at sales@gomeasure.ai — we'll walk you through our security posture and complete your security questionnaire.