GoRefer Trust Center
Employee & Operational Security
Updated September 2026
About this page. The procedures and recovery times described here are our policies and targets. They are not an independent audit, a contractual SLA or proof that a scheduled review has taken place. For current details, assessment reports and records, make a request through the Trust Portal.
The strongest technical controls can be undermined by insufficient operational security practices. GoRefer treats employee access management, training, and offboarding as first-class security controls — not HR paperwork.
This page describes our staff-security policy. It is not a record that any particular check or review has taken place; to confirm screening, training, access reviews or offboarding, ask us for the records.
Pre-Employment & Contractor Screening
Updated September 2026
Screening Process
Background verification
Our policy requires identity and employment-history checks before anyone gets access to production systems or customer data; completion records on request
Reference checks
Professional references required for senior engineering and operations roles
NDA on day one
Our policy requires a confidentiality agreement before access is granted; ask us to confirm signed agreements
Security policy acknowledgement
GoRefer's Acceptable Use Policy and Information Security Policy are acknowledged in writing before access is provisioned
Contractor & Vendor Access
No standing access for contractors
Contractors receive time-limited, scoped access that expires automatically at engagement end
Same MFA requirements
Contractors accessing production infrastructure are subject to the same MFA and VPN requirements as full-time staff
DPA or NDA required
Any third-party individual with access to systems that may process customer data must execute a DPA or NDA
Periodic access reviews
Contractor access is reviewed at 90-day intervals and revoked if no longer needed
Staff Access Controls
Updated September 2026
Our policy calls for role-based access and quarterly reviews. The table shows the intended access for each role; records of actual permissions, support access and completed reviews are available on request.
| Staff Role | Prod DB Access | Customer Data | MFA | Notes |
|---|---|---|---|---|
Engineering (General) | No | No | Yes | Access to staging and development environments only |
Engineering (Senior / Infra) | Read-only via VPN + MFA | Restricted by staff permissions | Yes (mandatory) | Current permissions and approvals: details on request |
Operations / Support | No | Approved support workflows | Yes | Access depends on approved support workflows |
Platform Admins | Audited access via isolated 2FA portal | Privileged workflows may access customer data | Yes — separate isolated auth system | Privileged authentication and workflow-specific audit records |
Sensitive-field encryption and privileged access
Encrypted fields can only be read with GoRefer's encryption key. Authorized parts of the application and GoRefer support staff may access customer data, and uploaded documents can contain readable personal information. Staff permissions and approved access procedures remain essential.
Isolated Operations Portal
Updated September 2026
GoRefer's own administrators use a privileged sign-in and platform roles. Administrator pages and firm pages are part of the same product; a separate login does not mean separate infrastructure.
Authentication Requirements
Platform-administrator accounts use a separate, privileged sign-in
Privileged authentication supports two-factor verification
IP restrictions: details on request
Sessions expire according to the privileged sign-in settings
Auditability
Supported administrative operations record actor and action details
Audit records are chained to support integrity checks; they are not kept in unchangeable storage
What is logged varies by feature; ask for the records of a specific operation
Log export available for compliance reviews
Security Training Program
Updated September 2026
Our training policy covers the topics and target schedule below. To confirm completion, ask us for attendance, assessment and access-review records.
| Training Topic | Frequency | Audience | Format |
|---|---|---|---|
Security Awareness Fundamentals | Annual | All staff | Interactive — completion tracked |
GDPR & Data Privacy Obligations | Annual | All staff | Written + assessment |
IRS Publication 4557 Requirements | Annual | Engineering, Product | Policy acknowledgement |
Secure Coding Practices (OWASP) | Annual + on-hire | Engineering | Guided course |
Incident Response Procedures | Annual + tabletop exercises | Engineering, Operations | Tabletop simulation |
Phishing & Social Engineering | Quarterly simulation | All staff | Simulated attack + debrief |
Password & Secrets Management | On-hire + annual refresh | All staff | Policy + tool training |
Offboarding & Access Revocation
Updated September 2026
Same-day access-revocation policy
Our offboarding policy calls for access to be revoked on the day someone leaves. The checklist below shows the intended steps; completed checklists and access records are available on request.
Day-of Revocation
All SSO and identity provider access revoked
All active sessions invalidated
SSH keys and API tokens rotated
Production system credentials changed
Within 24 Hours
All third-party tool access confirmed revoked
MFA devices deregistered
Email forwarding rules reviewed
Code signing certificates revoked
Post-Departure Review
Access audit of departing staff's permissions
Review of recent activity logs
NDA reminder and IP assignment confirmation
Checklist retained in HR records