How we protect the data our customers entrust to us and the candidate data in our platform. Last updated: 5 October 2026.
The Perfect platform is hosted on Google Cloud in the United States (Iowa), with EU hosting available on request. Every third party that processes data for us is listed, with its purpose and location, on our Sub-processor List.
Data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest in our databases, storage and backups. Encryption keys are managed in Google Cloud Key Management Service.
All staff sign in through single sign-on with two-factor authentication. Access to production systems, databases, source code and backups is limited to the people who need it, granted by role, approved before it is given, and reviewed every quarter. Access is removed promptly when someone leaves.
Each customer account is isolated from every other. Every request to our systems is limited to a single account, enforced in the application on every query, so one customer can never see another customer's data.
Every code change is reviewed and approved by a second engineer before it can be merged. Code dependencies are scanned for known vulnerabilities, and a failed scan or failed test blocks the change from reaching production. Development, test and production environments are kept separate.
Our production environment is monitored continuously for suspicious activity, and security logs are kept for 90 days. We follow a written incident response plan, and we notify affected customers without undue delay, and in any event within 72 hours, of confirming a security incident that affects their data.
Databases are backed up daily and replicated across multiple availability zones. We test our ability to restore data and recover from a disaster at least once a year.
Everyone who joins GoPerfect goes through background screening suited to their role, signs a confidentiality agreement, and completes security and privacy training when they join and every year after. Company laptops are encrypted, locked automatically and protected against malware.
We use AI models from Anthropic and Google through their enterprise services, under terms that prohibit them from training on your data. We do not use customer data to train general AI models, and what our platform learns from your account stays in your account.
If you believe you have found a security vulnerability in GoPerfect or the Perfect platform, please email security@goperfect.com with enough detail for us to reproduce it. Please give us a reasonable time to fix it before disclosing it publicly, and do not access or change data that is not yours. We will acknowledge your report and keep you updated.
Talent Fabric Ltd, trading as GoPerfect, Har Sinai 1, Tel Aviv, Israel.