Security, privacy,
and AI ethics.
Recruit touches candidate careers and company data. Here's exactly how we protect both.
GDPR Compliant
EU data protection
SOC 2 Type II
In progress
ISO 27001
Roadmap 2026
99.9% Uptime SLA
Live at status.comsalo.com
How we protect
your data.
Infrastructure built for regulated industries from day one.
Encryption at rest & in transit
All data encrypted using AES-256 at rest. All connections enforced over TLS 1.3. Keys rotated automatically.
Infrastructure
Hosted on AWS EU (Frankfurt). No data leaves the European Economic Area without explicit written consent.
Access control
Role-based access control for all platform features. Audit logs on all sensitive operations. Zero standing privileges.
Subprocessors
We maintain a public list of all third-party services that process your data. Updated on every change.
Our commitments
on AI fairness.
AI that affects hiring decisions carries moral weight. These are implemented behaviors, not aspirations.
We don't see names, genders, or ages
Our CV scoring model is designed to ignore personally identifiable signals. It evaluates skills and experience only.
Scores are explainable
Every AI score comes with a full breakdown — which skills matched, which were missing, and why the score landed where it did.
Humans stay in the loop
AI scores are recommendations, not final decisions. HR professionals retain full authority over every hiring decision.
Quarterly bias audits
We run structured evaluations of our models every quarter to detect and correct distributional bias. Results are published in Research.
Your data doesn't train our models
Candidate and company data submitted through Recruit is never used to train or fine-tune AI models without explicit written consent.
Opt-out of AI evaluation
Enterprises can request a human-review-only mode for any pipeline. AI scoring becomes advisory or is disabled entirely.
Third-party services.
Last updated: April 2026
| Service | Purpose | Region |
|---|---|---|
| AWS | Infrastructure & hosting | EU (Frankfurt) |
| Supabase | Database & auth | EU |
| Resend | Transactional email | US |
| OpenAI | Speech-to-text (Whisper), Text-to-speech | US |
| Groq | AI inference — interview scoring | US |
| Anthropic | AI inference — enterprise chat | US |
| Cloudflare | CDN & DDoS protection | Global |
Access, correct,
or delete your data.
Under GDPR you have the right to access, correct, export, or delete your data at any time. Candidates can also request deletion of interview recordings and scores.