C2C Central
Security & compliance

Your firm's data, fenced and protected.

C2C Central holds your bench, submissions, and compliance records — the lifeblood of your business. We treat that responsibility seriously: absolute firm-level isolation, encryption everywhere, strict role-based access, and a complete audit trail.

The non-negotiable

One firm can never see another firm.

In staffing, your bench and vendor relationships are the business. Firm-level data isolation is the one rule C2C Central will never bend. Every query, every document, every metric is scoped to your firm and yours alone — verified at the data layer on every request.

How we protect it

Security built into every layer

Not a checklist bolted on after launch — these controls are part of how the platform is designed.

Absolute firm-level isolation

Your firm's data is fenced off completely. No Owner, Manager, or Recruiter can ever see a candidate, submission, or metric belonging to another firm. Isolation is enforced at the data layer, not just the UI.

Encrypted in transit and at rest

All traffic is protected with TLS, and data — including resumes and compliance documents — is encrypted at rest in Google Cloud. Keys are managed by the platform, never exposed to clients.

Role-based access control

Owners see the whole operation, Managers see their team, and Recruiters see their queue. Every screen and action respects the role, so people only ever touch what they should.

Audit logging of every action

Every application, submission, and response is logged with who, what, and when. The same trail that powers recruiter performance also gives you a tamper-evident record for compliance reviews.

Authentication you control

Authentication runs on Firebase Auth with enforced password policies and session management. Sensitive actions require an active, authenticated session scoped to a single firm.

Hardened cloud infrastructure

C2C Central runs on Google Cloud Run with isolated, per-firm data partitions in a dedicated database, behind Google's physical and network security.

Role-based access

People see exactly what their role allows

Three roles, three scopes. Access is enforced on every screen and every action.

Owner / Director

Everything in the firm

All recruiters, all candidates, all marketing spend, and full performance — and nothing from any other firm.

Manager

Their team only

Their recruiters' candidates, assignments, and performance — scoped to the team they manage.

Recruiter

Their daily queue

The candidates and jobs assigned to them, with their own application and submission activity.

Standards & certifications

Aligned to the standards your clients ask about

Where we are today, stated plainly — no overclaiming.

SOC 2

In progress

Type II program underway, covering security, availability, and confidentiality controls.

GDPR

Aligned

Data subject rights, processing records, and a Data Processing Addendum available.

CCPA

Aligned

Disclosure, deletion, and opt-out rights honored for California residents.

Data residency

US

Firm data is stored in US-based Google Cloud regions.

Audit logging

A record of every recruiter action.

C2C Central logs every application, submission, and response with the actor, the action, and the timestamp. The same trail that powers recruiter scorecards doubles as a compliance record — so when a client or auditor asks who did what and when, you have the answer.

Activity log

Submitted candidate to req #4821

Recruiter · A. Rao

10:42

Applied on Dice — Java/AWS role

Recruiter · J. Patel

10:39

Reassigned bench candidate

Manager · S. Kim

10:31

Logged interview response

Recruiter · A. Rao

10:18

Common questions

Security & compliance FAQ

How does C2C Central keep one firm's data separate from another's?

Firm-level data isolation is absolute and enforced at the data layer. Every record is scoped to a single firm, and access checks ensure no Owner, Manager, or Recruiter can ever read or write data belonging to another firm — not through the interface and not through the API.

Is C2C Central SOC 2 compliant?

C2C Central's SOC 2 Type II program is in progress, covering security, availability, and confidentiality. In the meantime the platform already runs encryption in transit and at rest, role-based access control, and full audit logging.

Is data encrypted?

Yes. All data is encrypted in transit with TLS and at rest in Google Cloud, including resumes and compliance documents stored in Google Cloud Storage.

Does C2C Central support GDPR and CCPA?

Yes. C2C Central is aligned with GDPR and CCPA, supporting data subject access, deletion, and opt-out rights, with a Data Processing Addendum available to firms that need one.

Can I see who did what in my firm?

Yes. Every recruiter action — applications, submissions, and responses — is logged with the actor, the action, and the timestamp, giving you a complete audit trail for both performance and compliance.

Security questions before you switch?

Talk to our team about isolation, encryption, audit logging, and our SOC 2 program — or request a DPA.