Trust
How we protect your information
Last updated: September 2026
Candidates trust us with résumés, work histories, and eventually onboarding details. Clients trust us with hiring plans and compensation data. This page explains, in plain language, how that information is handled. For the legal treatment of personal data and your rights over it, see our Privacy Policy.
Where your information lives
Candidate and client records are stored in a commercial applicant tracking and CRM platform operated by an established vendor, not on personal devices or ad-hoc spreadsheets. We choose platforms that maintain recognized independent security attestations, and we review a vendor’s current audit report before entrusting data to them.
An important distinction: a certification held by one of our vendors covers that vendor’s systems and controls — it is theirs, not ours, and we do not present it as a Pheenix Solutions certification. Pheenix Solutions does not currently hold its own SOC 2 or ISO 27001 certification. If your procurement process requires vendor attestation documents, contact us and we will provide what our platform vendors publish.
Encryption
This website is served over HTTPS, so anything you send through it is encrypted in transit. Our applicant tracking platform likewise encrypts data in transit and at rest using current industry-standard methods.
Who can see your information
- Access is limited to people who need it to do the work — principally the recruiter handling your search and the staff supporting them.
- Accounts are individual, never shared, and are protected by multi-factor authentication.
- Access is removed promptly when someone leaves or changes roles.
- We ask before we submit. Your résumé is not sent to an employer without your knowledge; we tell you who we are submitting you to first.
- We do not sell your personal information or share it with advertisers or data brokers.
What we collect, and when
During a search we need the ordinary contents of a résumé: contact details, work history, skills, and references you choose to provide. Highly sensitive identifiers — Social Security number, bank details, government ID, tax forms — are collected only after you have accepted an offer, through a secure onboarding process, and never as a condition of being considered for a role.
Anyone asking for those details earlier is not us. See our Fraud Alert.
How long we keep it
We retain candidate records while there is a live reason to — an active search, an ongoing placement, or your interest in future roles — and thereafter for as long as applicable employment and tax recordkeeping rules require. You may ask us to delete your information at any time; see Your rights & choices in the Privacy Policy.
Our own practices
- Company accounts and devices are password-protected, kept current with security updates, and use multi-factor authentication wherever the platform supports it.
- Staff are trained to recognize phishing and social-engineering attempts, which are the realistic threat to a firm our size.
- Background checks are conducted on employees with access to candidate records, consistent with applicable law.
- We minimize what we hold: if we do not need a piece of information to run a search, we prefer not to collect it.
This website
The site is a static website with no user accounts, no logins, and no database of visitors. Form submissions are transmitted over HTTPS to our form provider and delivered to us by email. We do not run advertising trackers or sell visitor data. Security headers are applied at the hosting layer to reduce common web risks.
If something goes wrong
No organization can promise that a breach will never happen; any provider that does is overselling. What we commit to is straightforward handling if it does: we will investigate promptly, work with the affected platform vendor, and notify affected individuals and clients as required by applicable law, telling you what happened, what information was involved, and what steps to take.
Reporting a security concern
If you believe you have found a vulnerability in this website, email it@pheenixsolutions.com and put “Security report” in the subject line so it reaches us quickly. Please include enough detail for us to reproduce the issue. We appreciate reports made in good faith and will not pursue action against researchers who report responsibly and avoid accessing other people’s data.
For questions about how your data is handled, or to exercise a privacy right, use the same address with “Privacy request” in the subject — see Your rights & choices.