Skip to content

Security and privacy

Consent-first people intelligence.

Cadence is designed around visible capture, human review, and an honestly labeled security maturity roadmap.

Last updated: June 2026

This page distinguishes production capability from roadmap work. Roadmap: security-maturity items, granular role-aware access, and SOC 2 Type II readiness remain labeled as Coming Q3 / roadmap until shipped.

Employees know when capture is happening

Meeting capture is designed to be consent-first and visible to participants. Confirm retention terms in the current approved agreement before relying on them.

Managers approve what becomes the record

AI can draft summaries and coaching, but humans approve memorialized meeting records and own any external communication.

Procurement gets an honest security picture

Production capabilities and roadmap items are labeled separately, so buyers can distinguish current access from future work.

Security architecture

Specifics for buyers, legal, and IT.

Cadence holds sensitive workforce data: 1:1 conversations, performance context, ER cases, recognition, goals, and survey signal. The trust model keeps current controls explicit and roadmap controls clearly labeled.

Infrastructure

Production workloads run on Google Cloud Platform with containerized services, managed PostgreSQL, and Redis used for cache-only paths.

Access control

Current workspace access is role/entitlement scoped; deeper persona policy surfaces are not a current purchase promise.

Audit logging

Administrative actions, exports, and sensitive-record access generate audit records designed for review and export workflows.

AI data handling

AI drafts, summarizes, and coaches; humans own judgment and outbound communication.

Vulnerability management

Dependency and container scanning are part of the build path; SOC 2 Type II readiness is roadmap until complete.

Meeting consent

All-party consent. No silent capture.

Meeting content is inherently sensitive. Cadence is designed so recording and AI processing are visible, opt-in, revocable, and fail-closed.

  1. 1Tenant enables recording only after privacy prerequisites are complete.
  2. 2Every meeting starts in non-recorded mode; capture is never passive.
  3. 3Participants see what is captured, why, retention, and a clear decline path.
  4. 4Capture unlocks only after all required participants consent.
  5. 5Any participant can revoke consent; revocation stops future capture and processing.

Compliance posture

Honest status, not vague assurance.

AreaCadence postureStatus
GDPRProcessor posture for customer workforce data; EU employee recording requires lawful-basis mapping, DPIA, and non-recording fallback.In review
CCPA / CPRAService-provider posture for customer workforce data.In review
SOC 2 Type IIControls and evidence collection are roadmap/readiness work, not a completed certification claim.Roadmap
AI governanceAI drafts, summarizes, and coaches; humans own judgment and outbound communication.Current design principle

Responsible disclosure

Report a security issue before it affects customers.

Cadence welcomes good-faith vulnerability reports for the web application, API, and MCP server. Please avoid accessing, changing, or retaining customer or employee data beyond what is strictly necessary to demonstrate the issue.

Owner

Cadence Legal owns intake with Security as technical DRI. Sarah Mitchell, General Counsel, is accountable for disclosure governance and launch gating.

Channel

Send reports to security@cadencehr.ai with affected host, endpoint, tenant context, reproduction steps, impact, and any proof-of-concept material.

Triage SLA

Cadence acknowledges credible submissions within 2 business days and provides an initial severity assessment or follow-up questions within 5 business days.

Severity handling

Critical issues involving authentication bypass, tenant isolation, regulated data exposure, or write access are escalated immediately to Security, Legal, and the executive incident channel.

Safe harbor

Cadence will not pursue legal action for good-faith research that avoids privacy harm, data destruction, service disruption, social engineering, extortion, or access beyond what is necessary to prove the issue.

Scope

Public Cadence web surfaces, the customer-approved REST API, and the MCP server are in scope. Customer data exfiltration, employee impersonation, and physical attacks are out of scope.

How to submit

Email security@cadencehr.ai with a concise report. Cadence may request coordinated disclosure timing for issues that could expose customer environments, employee data, authentication controls, or tenant isolation boundaries.