Trust
Security at Afren
Last updated: September 22, 2026
How we protect your account
- Sign-in options: passkeys, two-factor authentication, and Google or GitHub sign-in. Passwords are stored only as salted hashes.
- Sessions: short-lived access tokens scoped to what each part of the Platform needs.
- Sensitive requests: sign-in and account-recovery requests are encrypted in the browser before they are sent, on top of TLS.
How we protect your data
- In transit: all traffic uses HTTPS, with HSTS on our domains.
- At rest: our production database and file storage are encrypted, and the database is not reachable from the public internet.
- Backups: automated backups, including copies that cannot be altered or deleted for a retention period and a copy held with a separate provider.
- Secrets: credentials live in our cloud provider's managed configuration, not in source code.
- Payments: card details go straight to Stripe or Paystack. Afren never sees or stores full card numbers.
- Your choices: consent is recorded with the version of the policy you agreed to, and you can export or delete your data (see our Privacy Policy).
AI and hiring decisions
- Every call to an AI model carries a platform-wide guardrail against prompt injection and leaking data or secrets.
- AI-assisted hiring decisions are logged, can be reviewed by a person on request, and are tested for bias with an automated harness.
Compliance roadmap
We are building our security programme against the SOC 2 Trust Services Criteria (security, availability, confidentiality) and ISO/IEC 27001:2022. Afren is not yet SOC 2 audited or ISO 27001 certified. We will say so here, with the report or certificate details, once an independent auditor has issued them.
If your organisation needs our security questionnaire answers or a list of subprocessors, email business@afren.ai.
Reporting a vulnerability
If you think you have found a security issue, email business@afren.aiwith the subject “Security report”. Include what you found, how to reproduce it and what it affects. We aim to acknowledge reports within 5 business days and to keep you updated until it is fixed.
While testing, please:
- only use accounts you own or have permission to use, and do not access, change or delete other people's data;
- not run denial-of-service, spam or social-engineering tests, or test physical security;
- give us a reasonable time to fix the issue before you tell anyone else.
We will not pursue or support legal action against anyone who reports an issue in good faith and follows these guidelines. We do not currently run a paid bug bounty.
Machine-readable contact: /.well-known/security.txt