Skip to content

GoRefer Trust Center

Employee & Operational Security

Updated September 2026

About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.

The strongest technical controls can be undermined by insufficient operational security practices. GoRefer treats employee access management, training, and offboarding as first-class security controls — not HR paperwork.

This page describes our staff-security policy. It is not a record that any particular check or review has taken place; to confirm screening, training, access reviews or offboarding, ask us for the records.

Staff MFA Policy
Least Privilege
Training policy
Security Audit Records

Pre-Employment & Contractor Screening

Updated September 2026

Screening Process

  • Background verification

    Our policy requires identity and employment-history checks before anyone gets access to production systems or customer data; completion records on request

  • Reference checks

    Professional references required for senior engineering and operations roles

  • NDA on day one

    Our policy requires a confidentiality agreement before access is granted; ask us to confirm signed agreements

  • Security policy acknowledgement

    GoRefer's Acceptable Use Policy and Information Security Policy are acknowledged in writing before access is provisioned

Contractor & Vendor Access

  • No standing access for contractors

    Contractors receive time-limited, scoped access that expires automatically at engagement end

  • Same MFA requirements

    Contractors accessing production infrastructure are subject to the same MFA and VPN requirements as full-time staff

  • DPA or NDA required

    Any third-party individual with access to systems that may process customer data must execute a DPA or NDA

  • Periodic access reviews

    Contractor access is reviewed at 90-day intervals and revoked if no longer needed

Staff Access Controls

Updated September 2026

Our policy calls for role-based access and quarterly reviews. The table shows the intended access for each role; records of actual permissions, support access and completed reviews are available on request.

Staff RoleProd DB AccessCustomer DataMFANotes
Engineering (General)
NoNoYesAccess to staging and development environments only
Engineering (Senior / Infra)
Read-only via VPN + MFARestricted by staff permissionsYes (mandatory)Current permissions and approvals: details on request
Operations / Support
NoApproved support workflowsYesAccess depends on approved support workflows
Platform Admins
Audited access via isolated 2FA portalPrivileged workflows may access customer dataYes — separate isolated auth systemPrivileged authentication and workflow-specific audit records

Sensitive-field encryption and privileged access

Encrypted fields can only be read with GoRefer's encryption key. Authorized parts of the application and GoRefer support staff may access customer data, and uploaded documents can contain readable personal information. Staff permissions and approved access procedures remain essential.

Isolated Operations Portal

Privileged access

Updated September 2026

GoRefer's own administrators use a privileged sign-in and platform roles. Administrator pages and firm pages are part of the same product; a separate login does not mean separate infrastructure.

Authentication Requirements

  • Platform-administrator accounts use a separate, privileged sign-in

  • Privileged authentication supports two-factor verification

  • IP restrictions: details on request

  • Sessions expire according to the privileged sign-in settings

Auditability

  • Supported administrative operations record actor and action details

  • Audit records are chained to support integrity checks; they are not kept in unchangeable storage

  • What is logged varies by feature; ask for the records of a specific operation

  • Log export available for compliance reviews

Security Training Program

Updated September 2026

Our training policy covers the topics and target schedule below. To confirm completion, ask us for attendance, assessment and access-review records.

Training TopicFrequencyAudienceFormat
Security Awareness Fundamentals
AnnualAll staffInteractive — completion tracked
GDPR & Data Privacy Obligations
AnnualAll staffWritten + assessment
IRS Publication 4557 Requirements
AnnualEngineering, ProductPolicy acknowledgement
Secure Coding Practices (OWASP)
Annual + on-hireEngineeringGuided course
Incident Response Procedures
Annual + tabletop exercisesEngineering, OperationsTabletop simulation
Phishing & Social Engineering
Quarterly simulationAll staffSimulated attack + debrief
Password & Secrets Management
On-hire + annual refreshAll staffPolicy + tool training

Offboarding & Access Revocation

Updated September 2026

Same-day access-revocation policy

Our offboarding policy calls for access to be revoked on the day someone leaves. The checklist below shows the intended steps; completed checklists and access records are available on request.

Day-of Revocation

  • All SSO and identity provider access revoked

  • All active sessions invalidated

  • SSH keys and API tokens rotated

  • Production system credentials changed

Within 24 Hours

  • All third-party tool access confirmed revoked

  • MFA devices deregistered

  • Email forwarding rules reviewed

  • Code signing certificates revoked

Post-Departure Review

  • Access audit of departing staff's permissions

  • Review of recent activity logs

  • NDA reminder and IP assignment confirmation

  • Checklist retained in HR records