Skip to main content

The architecture, the controls, the boundaries.

What XylaWorks runs on, how it is governed, what each party in a deployment can see, and which frameworks the compliance program is built to. For procurement, IT, information security, and compliance reviewers evaluating XylaWorks for institutional deployment.

For the methodology itself — what the 3-Dimensional Leader Framework measures and how assessments are produced — see the framework section of the storefront.

Enterprise cloud infrastructure. Managed as code. Audit-logged end to end.

XylaWorks runs on dedicated enterprise cloud infrastructure with workload identity for service authentication, private networking for data and AI services, and encryption in transit and at rest. Infrastructure is managed as code. Production and staging run as separated environments with manual gating between them.

Deployment
Containerized cloud infrastructure managed entirely as code, across physically separated staging and production environments.
Edge
Enterprise Web Application Firewall (WAF) and DDoS mitigation inspecting traffic at the global edge before routing to isolated application ingress.
Application
Horizontally scaled application services and asynchronous workers operating within private networking boundaries.
Data
Managed relational databases, in-memory caches, and document stores isolated on private endpoints. Keys and connection credentials are centralized in hardware-backed secure vaults.
AI services
Governed foundation model services accessed via enterprise identity over private networking. Zero candidate data is retained by providers or used for model training.
Observability
End-to-end tracing, metrics, and dependency telemetry. Immutable, insert-only audit logging across application, worker, and AI operations.

Controls scoped to what the system actually does.

  • Centralized secrets and workload identity.

    Cloud workload identity authenticates all inter-service communication. Application secrets and database connection credentials reside in centralized vaults and are injected at container startup without hardcoding.

  • Private data paths.

    Data stores and AI services are reached exclusively over private endpoints, eliminating exposure to the public internet.

  • Encryption in transit and at rest.

    TLS 1.3 encryption in transit across all public and internal endpoints. AES-256 encryption at rest across all databases, caches, and storage volumes.

  • Session handling.

    HTTPOnly session cookies for web applications. Session tokens are never exposed to browser scripts, protecting against token interception and XSS extraction.

  • Content safety on AI outputs.

    Every AI-generated output passes through dedicated content safety filtering before it reaches the user.

  • Immutable audit logs.

    Audit logs are insert-only and immutable at the application layer. Every AI execution, access-code redemption, and approval-state transition is recorded with actor and timestamp.

  • Gated production promotions.

    Production environments run completely independent from staging and require explicit manual authorization of verified release candidates before deployment.

AI-powered. Human-governed.

AI-generated outputs are governed by a three-state approval architecture — processing, awaiting approval, approved. The approval state is a database field, not a user interface flag. Candidate deliverables are released only upon reaching approved status, with flagged outputs held in awaiting approval for human review before release.

The governance pipeline is the architecture. Outputs are structurally validated against the 3-Dimensional Leader Framework, filtered through dedicated content safety models, and audit-logged end to end. Recommendations are anchored to dimensional signals and evidence identified in the candidate's submitted materials.

A governed analysis pipeline that can evolve without changing the product contract.

The XylaWorks assessment engine orchestrates governed process groups, skills, scoring logic, and model layers to apply the framework at platform scale. The architecture is built so the analysis stack can keep evolving without changing what candidates and organizations rely on: consistent inputs, governed scoring, traceable outputs, and controlled state transitions.

Governance here operates at the system level. It is not a claim of per-candidate human review. The platform does not guarantee placement, predict a specific hiring outcome, certify candidates, or independently verify the accuracy of the material a candidate submits.

Organizations purchase career-intelligence seats, not workforce-management software.

A seat entitles one candidate to the sponsored XylaWorks experience. An access code is the redemption mechanism for that seat — it is not the product, and it is not the unit of commercial agreement.

XylaWorks does not recruit, staff, place, schedule, dispatch, or manage workers for organizational customers.

What each party sees. What stays private.

XylaWorks operates across four relationships with different data boundaries. The matrix below is the authoritative reference for what is visible in each. Channel pages reference this matrix; this is where the architectural lines are drawn.

Data categoryCandidateEmployerInstitutionWorkforce Program
Access code redemption (named, timestamped)N/AVisibleVisibleVisible
Engagement signals (active flag, frequency)FullNot visible beyond redemptionPer-participant + aggregatePer-participant + aggregate
Uploaded materials (résumé, submitted artifacts)FullNot visibleRead-onlyRead-only
Scoring inputs and assessment factors used to produce the readFullNot visibleRead-onlyRead-only
Score history and change across runsFullNot visibleRead-only + aggregateRead-only + aggregate
Platform outputs (guidance, strategy, documents)FullNot visibleRead-onlyRead-only
Tier selected and upgrade activityFullNot visibleVisibleVisible
Positioning scoreFullNot visibleRead-onlyRead-only
Candidate reflective inputs (narrative, direction)FullNot visibleNot visibleNot visible
Aggregate cohort / program reportingN/ARedemption-level onlyAvailableAvailable

The candidate's reflective inputs — the personal narrative and direction the candidate provides to ground the assessment — remain private to the candidate across every channel. This is the one boundary that does not vary by deployment.

Score reporting distinguishes observed movement from causal attribution. Where a later run scores higher than an earlier one, that is reported as observed change in the record the platform read. XylaWorks does not claim to have caused the movement; a causal claim would require an evaluation design that supports it, and none is asserted here.

SOC 2-aligned governance. Framework-mapped.

The compliance program is built on the AICPA Trust Services Criteria as the primary framework and is mappable to NIST CSF 2.0 and ISO/IEC 27001:2022 Annex A. Twelve core security and governance control domains structure the program:

  • Information Security — the umbrella commitment governing the information security management program.
  • Access Control — provisioning, modification, review, and revocation of access.
  • Data Classification and Handling — classification scheme and handling requirements by sensitivity.
  • Encryption and Key Management — cryptographic protection in transit and at rest, key lifecycle.
  • Change Management — review, testing, authorization, and traceability of all production changes.
  • Vulnerability Management — identification, prioritization, and remediation of vulnerabilities.
  • Incident Response — detection, containment, eradication, recovery, and post-incident review.
  • Business Continuity and Disaster Recovery — recovery objectives, backups, and tested recovery capability.
  • Vendor and Sub-processor Management — diligence, contracting, monitoring, and offboarding of third parties.
  • Risk Assessment and Management — risk identification, evaluation, and treatment.
  • Human Resources Security — personnel screening, training, and access lifecycle.
  • Acceptable Use — permitted use of company systems and data.

SOC 2 Type II

Gap assessment completed against AICPA Trust Services Criteria. Certification is on the product roadmap.

GDPR and CCPA

Subject access request handling is implemented via a dedicated data export service. Data deletion follows a documented runbook with defined completion windows.

Institutional deployments

The reporting boundaries above are enforced at the data layer. Institutional compliance specifics — including scope of student record handling under applicable frameworks — are reviewed in the procurement briefing for each deployment.

HECVAT

A completed HECVAT (Higher Education Community Vendor Assessment Tool, v4.1.6) is available to institutions and workforce programs on request as part of the procurement briefing. The assessment covers the Organization, Product, Infrastructure, IT Accessibility, AI, and Privacy sections. Request it through the briefing form.

The 3-Dimensional Leader Framework.

Every assessment the platform produces is built on the 3-Dimensional Leader Framework — Demonstrated Competence, Professional Credibility, Meaningful Contribution. The full methodology is described on the framework section of the storefront.

Evaluating the platform for your organization?

A briefing covers the technical architecture, security posture, data-handling practices, and compliance mapping specific to your channel and framework.

Confidential. No obligation.