Source
Security / trust page — Ashby
Checked for Ashby on 30 Sep 2026
- Page
- https://www.ashbyhq.com/resources/security
- Checked
- 30 Sep 2026, 13:03 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:2d4a91ad173ddeb9f642f3722bbc1db2dee1e0878f3316a1a00d11f5289af4e6
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
SOC 2 Report an error
“Ashby is SOC2 compliant and Type 2 audited annually. Our SOC2 report is available to customers in our Trust Center.”
-
Provider Report an error
“We host Ashby using comprehensively hardened infrastructure-as-a-service (IaaS) platforms from Amazon Web Services.”
-
Last updated Report an error
“Last updated December 20, 2024”
-
Trust center Report an error
“We've consolidated all relevant security documentation in our Trust Center”
-
Authentication Report an error
“Ashby allows authentication from Google Workspace (formerly GSuite), Office 365 corporate accounts, magic links (sent via email), and SSO via SAML and OIDC. Ashby does not support password authentication.”
-
Permissions Report an error
“Ashby supports flexible permission levels for teammates. Permission levels can be set globally or within specific departments, jobs, and other organizational data.”
-
Encryption in transit Report an error
“Our web servers encrypt data in transit using the industry standard for HTTPS security (TLS 1.2 and TLS 1.3) to protect requests against eavesdroppers and man-in-the-middle attacks. Our SSL certificates are 2048 bit RSA or 256 bit ECDSA, signed with SHA256.”
-
Encryption at rest Report an error
“All persistent data is encrypted at rest using industry-standard AES-256 algorithms.”
-
Security policies Report an error
“Ashby has developed a comprehensive set of security policies covering a range of topics. These policies are updated frequently and shared with all employees.”
-
Employee training Report an error
“All Ashby employees are trained on security best practices and awareness during onboarding. We perform annual disaster recovery and data restoration tests.”
-
Employee access controls Report an error
“We use IAM to manage and verify employee account identities and require two-factor authentication for apps that access critical infrastructure or customer data.”
-
Admin access logging Report an error
“All employee contracts include a confidentiality agreement.”
-
Code review deployment Report an error
“All changes to source code are subject to automated testing and any that affect security require pre-commit code review by a qualified engineering peer that includes security, performance, and potential-for-abuse analysis. All code is deployed to a staging environment for quality assurance and automated tests must pass prior to updating production services.”
-
Uptime and backups Report an error
“Ashby infrastructure utilizes multiple and layered techniques for increasingly reliable uptime, including the use of load balancing and task queues. Ashby uses highly redundant datastores, rapid recovery infrastructure, and point-in-time backups making unintentional loss of customer data very unlikely.”
-
Infrastructure hardening Report an error
“Ashby servers use Cloudflare and Amazon Web Services managed infrastructure which utilize firewalls to restrict system access from external and internal networks, DDoS mitigation, spoofing and sniffing protections, and port scanning.”
-
Pentests Report an error
“We engage third-party security experts to perform detailed penetration tests on the Ashby app and infrastructure.”
-
API auth Report an error
“Access to the Ashby RPC API endpoints requires an access key that can be regenerated on demand by customers.”
-
Oauth opt in Report an error
“Integrations with other apps are all opt-in and authenticate via OAuth or other applicable mechanisms required by the third party app. Integrations can be disabled at any time.”
-
Payment processing Report an error
“We use Stripe for payment processing and do not store any credit card information. Stripe is a trusted, Level 1 PCI Service Provider.”
-
Incident response Report an error
“Ashby implements a protocol for handling security events which includes escalation procedures, rapid mitigation, and post mortem.”
-
Security contact Report an error
“please send an email to security@ashbyhq.com, a carefully controlled and monitored email account.”
-
Entity Report an error
“© 2026 Ashby, Inc.”
1 fact read from this page is not shown because it could not be confirmed on the page as captured.
Scores citing this record
- The Data Protection Officer Applicant management & hiring workflow
- The Data Protection Officer HR handover, integrations & API
- The Data Protection Officer European sovereignty
- The Employer Branding Manager Applicant management & hiring workflow
- The Employer Branding Manager HR handover, integrations & API
- The Employer Branding Manager European sovereignty
- The HR IT Integrator Applicant management & hiring workflow
- The HR IT Integrator HR handover, integrations & API
- The HR IT Integrator European sovereignty
- The Skeptic Applicant management & hiring workflow
- The Skeptic HR handover, integrations & API
- The Skeptic European sovereignty
- The Talent Acquisition Lead Applicant management & hiring workflow
- The Talent Acquisition Lead HR handover, integrations & API
- The Talent Acquisition Lead European sovereignty
- The Works Council Advocate Applicant management & hiring workflow
- The Works Council Advocate HR handover, integrations & API
- The Works Council Advocate European sovereignty