Trust is the foundation of any HR technology platform. When organizations entrust their recruitment processes to AI-powered systems, they are sharing some of their most sensitive data — candidate personal information, assessment results, hiring decisions, and demographic data. Ensuring the security and privacy of this data is not just a technical requirement; it is a legal obligation and a competitive differentiator. This page details the security certifications, compliance frameworks, and data protection protocols that govern our AI recruitment platform.
SOC 2 Type II Certification
SOC 2 (System and Organization Controls 2) is a voluntary compliance standard developed by the American Institute of CPAs (AICPA). It specifies how organizations should manage customer data based on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. A Type II report goes beyond a point-in-time assessment, demonstrating that controls are not just designed appropriately but are operating effectively over an extended period — typically six to twelve months.
Our platform undergoes annual SOC 2 Type II audits conducted by an independent third-party auditing firm. The audit evaluates controls across all five trust service criteria, with particular emphasis on security (protection against unauthorized access) and confidentiality (protection of sensitive information throughout its lifecycle). The audit report is available to enterprise customers under nondisclosure agreement. Key controls include: encryption of data at rest and in transit, role-based access control (RBAC), multi-factor authentication (MFA) for administrative access, automated session timeouts, comprehensive audit logging, and incident response procedures tested through regular tabletop exercises.
GDPR Compliance Framework
The General Data Protection Regulation (GDPR) sets the global standard for data privacy and applies to any organization processing the personal data of individuals in the European Union, regardless of where the organization is based. Our GDPR compliance framework is built on the principles of data minimization, purpose limitation, transparency, and individual rights.
We maintain a comprehensive Data Processing Agreement (DPA) that meets the requirements of GDPR Article 28, covering the scope and purpose of processing, the types of personal data involved, the categories of data subjects, and the obligations and rights of both the controller (the customer organization) and the processor (our platform). Data subjects can exercise their GDPR rights — access, rectification, erasure, restriction of processing, data portability, and objection — through a dedicated privacy request portal. All data processing activities are documented in a Register of Processing Activities (ROPA) as required by GDPR Article 30.
ISO 27001 & ISO 27701
ISO 27001 is the international standard for information security management systems (ISMS), specifying requirements for establishing, implementing, maintaining, and continually improving an ISMS. Our certification, renewed annually through accredited certification bodies, covers all systems and processes involved in delivering our AI recruitment platform, from software development and infrastructure operations to customer support and professional services.
ISO 27701 extends ISO 27001 to cover privacy information management, providing a framework for complying with global privacy regulations including GDPR, CCPA, LGPD, and others. Our ISO 27701 certification demonstrates that our privacy management practices meet international best practices, including processes for privacy impact assessments, data breach notification, cross-border data transfer mechanisms, and vendor due diligence.
Data Residency, Encryption & Access Control
We offer data residency options across multiple geographic regions — United States, European Union, United Kingdom, Canada, Australia, and Japan — allowing customers to store data within specific jurisdictions to comply with local data sovereignty requirements. Data at rest is encrypted using AES-256 encryption, and data in transit is protected by TLS 1.3. Access to production systems is restricted to authorized personnel through role-based access control, with all access logged and audited. Administrative access requires multi-factor authentication, and privileged access management follows the principle of least privilege with just-in-time access elevation.
Conclusion
Our commitment to security and compliance is not a one-time achievement but an ongoing process of continuous improvement. We undergo regular penetration testing, vulnerability assessments, and compliance audits to ensure our controls remain effective against evolving threats and regulatory requirements. Enterprise customers can request our SOC 2 Type II report, ISO certificates, and DPA through our enterprise sales process.
Read more about our data privacy and encryption practices.