Security & Compliance

Enterprise-Grade Security

Your candidate data is precious. We protect it with industry-leading security practices and comprehensive compliance certifications.

Volume I — Certifications

Independently Verified

🔒

SOC 2 Type II

Independently audited for security, availability, and confidentiality. Annual recertification ensures ongoing compliance.

🇪🇺

GDPR Compliant

Full compliance with EU data protection regulations. Data residency options available for European customers.

🛡️

ISO 27001

International standard for information security management. Comprehensive controls across all operations.

Volume II — Security Measures

Defense in Depth

I

Encryption Everywhere

All data encrypted at rest using AES-256. TLS 1.3 for data in transit. Encryption keys managed with AWS KMS.

  • • Database encryption at rest
  • • Encrypted backups
  • • Secure key rotation
II

Access Controls

Role-based access control (RBAC) with granular permissions. Multi-factor authentication required for all users.

  • • SSO integration (SAML 2.0)
  • • MFA enforcement
  • • Session management
III

Infrastructure Security

Hosted on AWS with VPC isolation. Regular penetration testing and vulnerability scanning.

  • • DDoS protection
  • • Web application firewall
  • • Intrusion detection
IV

Monitoring & Logging

24/7 security monitoring with automated alerting. Comprehensive audit logs for all system access.

  • • Real-time threat detection
  • • Audit trail retention
  • • Incident response team
V

Data Privacy

We never sell or share candidate data. Data deletion requests honored within 30 days.

  • • Data minimization
  • • Right to erasure
  • • Privacy by design
VI

Business Continuity

Automated backups every 6 hours. 99.9% uptime SLA. Disaster recovery plan tested quarterly.

  • • Multi-region redundancy
  • • Point-in-time recovery
  • • Failover automation
Volume III — Compliance

Regulatory Compliance

GDPR (General Data Protection Regulation)

Full compliance with EU data protection laws. We provide data processing agreements (DPAs), support data subject access requests, and maintain EU data residency options.

Our privacy-by-design approach ensures candidate data is protected from collection through deletion.

CCPA (California Consumer Privacy Act)

Compliant with California privacy regulations. Candidates can request access to their data, request deletion, and opt-out of data sharing.

We provide clear privacy notices and honor all consumer rights under CCPA.

EEO Compliance

Support for Equal Employment Opportunity reporting requirements. Structured feedback reduces bias in hiring decisions.

Our analytics help identify and address potential bias in your recruiting process.

Volume IV — Security Contact

Report a Security Issue

If you discover a security vulnerability, please report it to our security team immediately. We take all reports seriously and respond within 24 hours.