Security

Security built into every step of hiring

EU hosting with encryption in transit and at rest, tenant isolation, role-based access, a three-year audit log and candidate privacy controls — documented here and in our published DPA, so IT and legal can review before they have to ask.

Security capabilities

What we put in writing

Nine controls you can hand to IT, legal or a DPO. Where a control is also a product feature, the card links to the page that shows it in detail.

Infrastructure

Hosted in the EU, encrypted in transit (TLS) and at rest. Each customer is a separate tenant — every query is scoped to your company — and integration secrets such as Slack tokens or service-account keys are stored encrypted at field level.

Two-step verification

Each person turns on a second step for their own sign-in: a time-based code from Google Authenticator, Microsoft Authenticator or any other authenticator app, or a one-time code by e-mail. Switching the app on issues ten single-use recovery codes, and the secret is held encrypted. Codes sent, passed, refused and locked out all land in the audit log.

Role-based access

Six roles — super admin, admin, hiring manager, recruiter, reviewer, assistant — plus job-level scoping. Hiring managers and reviewers only see the jobs and candidates they are assigned to.

Take a look

Audit log

Sign-ins, candidate and pipeline changes, exports, permission and settings changes, e-mails, integrations and billing events are logged with actor, IP and severity. Admins filter and search in the dashboard; exports to CSV or XLSX require an e-mailed one-time code and are logged themselves.

Retention & deletion

Retention is enforced by the product, not by policy alone: a nightly job deletes video interview answers after 60, 90 or 365 days according to the subscription, and candidate data follows the KVKK soft-delete schedule.

Candidate privacy

Every sourced or imported candidate receives a privacy notice with a personal privacy page; one click objects and the record is anonymized on the spot, and anyone still uninformed after 30 days is flagged to you. Our DPA and sub-processor list are published — no need to ask.

Take a look

Sensitive fields & consent

Admins choose which candidate fields count as sensitive — contact details, salary expectation, gender, birth date, address and GPA by default — and reviewers and assistants never see them. Talent-pool consent is captured on the apply form where you require it.

Take a look

Blind hiring

Switch it on per job and evaluators see applications without name, photo or gender until identity is revealed on purpose — and every reveal is written to the audit log.

Take a look

Candidate document verification

Ask a candidate for an official document, verify it and record the outcome. Criminal-record and health documents are stored only if the candidate explicitly consents while uploading; otherwise only the verdict is kept, and a file can never be required of them. Other documents the candidate attaches sit in private storage, visible to authorised users alone, and are erased on the date set for that item. The legal basis is always declared by a named person, and no automatic check ever moves or rejects a candidate.

Take a look

Data portability & exit

Leaving is a documented process, not a negotiation: on request we export your whole tenant — jobs, candidates, notes, scorecards, offers, audit records — as JSON with a file manifest. What is exportable and in which format is published in the Data Export Register.

Take a look
Data lifecycle

What happens to candidate data, step by step

The controls above, arranged the way a privacy review actually asks about them.

  1. 01

    Collect

    • Apply forms show your privacy notice and capture talent-pool consent where required
    • Admins define which fields are sensitive; reviewers and assistants never see them
    • Sourced or imported candidates get a privacy notice with a personal link; the uninformed are flagged after 30 days
  2. 02

    Use

    • Role-based access with job-level scoping for hiring managers and reviewers
    • Optional blind mode hides name, photo and gender until a logged reveal
    • Every candidate, pipeline and export action lands in the audit log
  3. 03

    Retain

    • Audit records kept three years, then purged on a schedule
    • Video answers expire after 60, 90 or 365 days by plan
    • Soft deletes keep the trail intact until legal retention ends
  4. 04

    Leave

    • Candidates object from their privacy page and the record is anonymized
    • Customers get a full tenant export as JSON plus a file manifest
    • Sub-processor changes are announced 30 days ahead to your privacy contact
Documents

Read the paperwork before you ask for it

Our DPA, sub-processor list, SLA and privacy notices are published and versioned. Send the links to legal instead of waiting for a PDF.

When a sub-processor changes, every active customer's privacy contact is e-mailed 30 days in advance, as the DPA requires.

Compliance made simple

GDPR, KVKK and CCPA, handled inside the product

The apply form picks the right privacy notice from the job's location and fills in your legal details. Candidates get their own privacy page; you get the paperwork already published.

EU · UK · EEA

GDPR

For jobs located in the EU, UK or EEA, the GDPR privacy notice is added to the apply form automatically.

  • Notice pre-filled with your legal entity and privacy contact
  • Art. 28 processing covered by our published DPA and sub-processor list
  • Personal privacy page for every candidate; one click to object
Türkiye

KVKK

For jobs located in Türkiye, the KVKK disclosure text (aydınlatma metni) is generated for you.

  • Legal name, address, MERSIS and KEP details filled in from your settings
  • Talent-pool consent captured and time-stamped on the apply form
  • Sourced candidates informed with a personal privacy link
United States

CCPA

For jobs located in the US, the CCPA notice is added to the apply form with your legal entity and contact.

  • Sensitive fields hidden from reviewers and assistants by default
  • Candidate objection anonymizes the record on the spot
  • Full tenant export available on request, in documented formats

Security reviews & questionnaires

Send your vendor questionnaire or third-party assessment to sales. We answer it in writing with the DPA, sub-processor list, Data Export Register and an infrastructure summary.

Start a security review

Found a vulnerability?

Write to our security inbox with steps to reproduce. We acknowledge reports, keep you informed while we fix, and credit you if you want to be credited.

security@hireall.com
Security FAQ

Security questions

Short answers for common questionnaire items.

The apply form selects the right privacy notice from the job's location — GDPR for the EU, UK and EEA, KVKK for Türkiye, CCPA for the US — and fills in your legal entity and contact details. Every candidate gets a personal privacy page and can object in one click; talent-pool consent is captured with a timestamp. Our DPA, sub-processor list and Data Export Register are published on the legal pages, and sub-processor changes are announced 30 days in advance.

Yes. Sign-ins, candidate and pipeline changes, exports, permission and settings changes, e-mails, integrations and billing events are recorded with actor, IP address and severity, kept for three years and purged on a schedule. Admins filter and search it in the dashboard; CSV or XLSX export is available on plans that include it and requires a one-time e-mail code.

Yes. Send the questionnaire or assessment to sales@hireall.com or through the contact sales form. We answer in writing and attach the DPA, the sub-processor list, the Data Export Register and an infrastructure summary covering hosting, encryption, tenant isolation, access control and retention.

Data is hosted in the EU, encrypted in transit and at rest. The infrastructure jurisdiction and the safeguards against unlawful government access are described in the Data Export Register. For other data-residency questions, email sales@hireall.com or use the contact sales form.

Candidates can object from their personal privacy page and the record is anonymized at once. Records deleted in the product are hidden immediately and permanently deleted by a scheduled job 30 days later; only records a legal obligation or a live dispute requires are kept longer, for that purpose alone. Timers run per data type — audit records after three years, video answers after 30 to 365 days according to the subscription, finished document checks on their own schedule, security logs after 12 months — and every deletion is written to the audit log. Application logs carry record identifiers, not names or contact details.

Talk to us

Need a security pack?

Send us your vendor questionnaire — we answer it with the DPA, sub-processor list and an infrastructure summary.

Talk to our team

Tell us about your roles and team size — we'll map Hireall to your hiring process and the plan that fits.

Contact sales Priced per company, not per seat