Skip to main content

Trust Package

Security, data handling, and procurement review in one place.

Blacklight separates public, partner, and administrative access; limits sensitive changes by role, organization, location, and recent authenticator verification; keeps request data tied to delivery and accountable operations; and records the evidence needed to investigate changes, recover work, and apply retention rules.

Current production posture

Partner access is server-scoped, sensitive actions require stronger authentication, public capability lookup and launch confirmation use hashed evidence while protected hosted-link records support stable-link reuse, and production releases are tied to reviewed source, verified migrations, health checks, and rollback inventory.

Blacklight Resumes · Public control summary, not a certification

Materials

Start with the control or data question your team needs answered

The packet gives one decision-ready overview. Topic summaries and the technical appendix add detail about access, retention, providers, incident handling, recovery, audit evidence, and AI processing without exposing secrets or internal runbooks.

Editorial rule

Claims stay limited to current evidence. Where a provider, professional review, or contractual commitment is still external, the package says so directly.

Security and service controls

Use these when the review is about security controls, privileged access, or continuity.

Data, privacy, and vendor handling

Use these when the review is about what enters the system, how long it stays, and which providers are involved.

Assurance boundary

What this package proves, and what it deliberately does not claim

The strongest trust document is precise about both safeguards and limits. These boundaries apply across the packet, appendix, and topic summaries.

01

Controls described here are operating controls

The packet reflects the current production architecture, access model, data lifecycle, and operational release posture rather than a future-state feature list.

02

Evidence is bounded to what Blacklight can verify

Blacklight distinguishes application evidence from provider guarantees and does not claim provider-side deletion, availability, or residency without separate support.

03

No certification is implied

The public package does not claim SOC 2 certification, a completed penetration test, a VPAT, attorney approval, formal WCAG conformance, or contractual recovery objectives.

04

The current service is adult-only

Blacklight does not activate K–12 or under-18 programs. Any future teen pathway requires separate product, privacy, contract, and legal review before intake can open.

Control coverage

The operating areas covered by the current packet

The summaries below state the current control position first, then route to deeper evidence only when a reviewer needs it.

Security and access controls

Admin and partner access are separate, partner visibility is limited by organization, role, and location, and sensitive changes require recent authenticator verification and audit evidence.

Data handling and retention

Request data stays tied to generation, delivery, support, billing, and accountable operations. Record-specific retention, minimization, legal-hold, and deletion workflows limit how long sensitive content remains.

AI usage and model handling

Applicant-facing AI is limited to bounded resume-generation and supporting analysis. Separate internal model workflows assist partner research, materials, quality assurance, and editorial work without replacing Blacklight’s official business records.

Service readiness and privacy practices

Production uses reviewed releases, explicit rollback inventories, monitored queue and service health, private request artifacts, a tracking-light public site, and documented incident and recovery boundaries.