Bank-level security.
Zero compromises.
Protecting 130,000+ candidate records and serving 21,348+ organisations with enterprise-grade security, EU-based hosting, and GDPR-compliant data handling since 1998.
How We Protect Your Data
Every security measure designed to give you complete peace of mind when handling sensitive candidate information.
EU-Based Data Hosting
Candidate and client data is stored on EU servers (Hetzner Online GmbH, Germany). Some processing does take place outside the EEA and we would rather name it than claim otherwise: Stripe processes payments in the USA/EU, Anthropic PBC generates industry content in the USA (no candidate personal data is sent), transactional email is delivered through our SMTP relay, and the business that operates this platform is based in British Columbia, Canada, so operator access to the database is itself a transfer. Each is covered by Standard Contractual Clauses or an adequacy decision. The full list is on our sub-processor page.
Strong Encryption
TLS 1.3 in transit. Encrypted disk volumes for the database and uploaded files. Account passwords are hashed with bcrypt and are not recoverable by us. API tokens are stored as SHA-256 hashes. Credentials you connect for an ATS integration are encrypted at rest rather than hashed, because we have to be able to send them to that provider on your behalf.
PCI DSS Level 1 Payments
Stripe Checkout processes all payments. We never see or store card details. Your financial data never touches our servers.
Access Controls
Candidate results are visible only to the client who commissioned the assessment. Every route that exposes a candidate record checks ownership before returning it. Administrative actions are written to an audit log.
GDPR-Compliant Retention
Candidate records are deleted 24 months after the last activity on them โ not anonymised in place. The candidate row, their sessions, results, answers, reports, report PDFs, notes, tags and review records are removed, and the identifying fields on the originating invitation are cleared. Earlier deletion is available on request under GDPR Article 17.
Breach Notification
Where we process candidate data on your behalf we are the processor, so if we become aware of a personal data breach we notify you without undue delay under GDPR Article 33(2) โ not on a 72-hour clock, which is your own duty to your supervisory authority under Article 33(1). Where we are the controller, we notify the relevant authority within 72 hours.
Zero Third-Party Data Sharing
Your candidate data is never shared, sold, or used for advertising. No AI training on your data without explicit consent. Candidate and client records are stored on EU servers; the processing that happens outside the EEA is named in full above, and each transfer is covered by Standard Contractual Clauses or an adequacy decision.
Get Data Processing AgreementCompliance & Documentation
Complete transparency with enterprise-grade compliance documentation available on demand.
Data Processing Agreements
Enterprise clients receive signed DPAs under GDPR Article 28 within 5 business days. Complete coverage of processing purposes, data categories, sub-processors, and data subject rights.
Request DPA Documentation โReporting a vulnerability
We have not commissioned an external penetration test or third-party security review, and we do not hold a security certification. What we do have is a responsible disclosure route: report a vulnerability and we will respond within five business days and will not pursue legal action against researchers acting in good faith.
Report Security Issues โQuestions about our security measures or data handling practices?
Ask Us About Security