Data protection
Consumer report data is handled through restricted workflows, documented retention practices, and privacy-aware support paths.
Trust and security
Background screening involves sensitive candidate and employer information. This center brings security, privacy, legal, FCRA, vendor diligence, and vulnerability disclosure resources into one place.
Operating posture
The strongest trust proof is not an old seal. It is clear process, careful data handling, documented legal resources, and a human support path when a report or rule needs attention.
Consumer report data is handled through restricted workflows, documented retention practices, and privacy-aware support paths.
Sensitive data is protected in transit with HTTPS and in the application through encrypted storage workflows for protected fields.
Database backup jobs and deployment rollback checks are part of the operating baseline, with production access limited to authorized operators.
Client, candidate, and operations workflows separate access by role so sensitive report activity is not handled like ordinary website traffic.
Public website, API health, deployment checks, backup jobs, security headers, and production logs are reviewed as part of site operations.
The public security contact file lives at /.well-known/security.txt and points researchers back to this disclosure hub.
Employment screening support includes permissible purpose review, authorization reminders, adverse action resources, and dispute handling paths.
Reports are reviewed by trained people before delivery. Information Direct does not position its reports as AI-only eligibility decisions.
Security researchers can report suspected vulnerabilities through the disclosure path below.
Procurement teams, government contractors, enterprise buyers, and regulated employers can use these resources to understand how Information Direct handles screening scope, legal terms, privacy, source fees, and candidate-facing obligations.
If you believe you found a security issue, email info@informationdirect.us with a concise report. Please include affected URL or endpoint, reproduction steps, expected impact, and a safe proof of concept if available.
FAQ
Yes. The security contact file is available at /.well-known/security.txt and points to this Trust and Security Center.
Email info@informationdirect.us with the affected URL, steps to reproduce, impact summary, and any safe proof of concept. Do not access, copy, change, or disclose candidate, client, or consumer report data.
Yes. Procurement and enterprise buyers can request security, legal, service, DPA, insurance, and capability statement materials through the contact form.
No. Information Direct provides background screening reports and workflow support. Employers remain responsible for hiring decisions, notices, disputes, and adverse action under applicable law.