SalesProof is designed with security, privacy, and responsible AI handling at its core. Built on enterprise-grade infrastructure and aligned with UK GDPR and England & Wales legal requirements.
Candidate and customer data encrypted in transit and at rest.
SalesProof does not sell candidate data or use customer assessment data to train public AI models.
Role-based permissions, MFA enforcement, and controlled production access.
Critical platform activity is logged and monitored for security and operational integrity.
AI-assisted assessment analysis includes integrity and authenticity controls.
Security controls aligned to enterprise SaaS expectations and UK GDPR obligations.
Security Overview
A summary of the legal frameworks and safeguards SalesProof operates under. Tap any topic to read more.
Privacy & Data Protection
Clear handling principles for every piece of personal data flowing through SalesProof from candidate assessments to customer workspaces.
Access Controls
Access Control Policy
MFA Security
Audit Logging & Monitoring
Critical platform activity is logged so we can investigate, learn, and respond.
Sign-ins, sign-outs, password and MFA changes are logged for security review.
Critical admin activity. Role changes, billing changes, workspace configuration. Is recorded.
Unusual login patterns and anomalous behaviour are flagged for follow-up.
Operational telemetry retained to support troubleshooting and forensic review if needed.
AI is a tool inside SalesProof. Not a substitute for hiring judgement. We design AI use to be transparent, evidence-based, and respectful of candidates.
AI helps surface signals from candidate responses; final scores follow our published methodology.
Submissions are screened for tell-tale signs of inauthentic or generated answers.
Behavioural patterns during assessments are reviewed to support fair, evidence-based hiring decisions.
Language and structure of candidate responses are analysed to identify deal-control evidence.
No public AI model training on customer candidate data.
Anonymised, aggregated patterns only. No candidate names, emails, employer names, or workspace data ever enter the benchmark model.
Security Reviews
Internal reviews of platform security posture, configurations, and access controls.
Automated scanning across application surfaces and infrastructure to detect known issues.
Continuous monitoring of third-party packages for security advisories and timely patching.
Hardening reviews across hosting, database, and authentication providers.
Engagement with external specialists for additional assessment when appropriate.
Vendor Management
SalesProof seeks to work with providers maintaining commercially reasonable security standards.
We welcome responsible disclosure from the security community. If you believe you've discovered a vulnerability, please contact us at:
security@salesproof.ioThis information is provided for general informational purposes and does not constitute legal advice, regulatory certification, SOC 2 certification, or warranty of uninterrupted security. SalesProof continues to invest in maturing its security and privacy programme.