To request a security review pack, a signed DPA, or our pen-test summary, write to security@recruitsphere.space.
1. Encryption
- All traffic to and from RecruitSphere is encrypted in transit with TLS 1.2 or higher. HSTS is enforced on production domains.
- Data at rest in our managed database and object storage is encrypted using AES-256.
- Application-level encryption is used for sensitive fields such as inbox OAuth refresh tokens and integration credentials.
- Backups are encrypted with separate keys.
2. Access control
- Customer workspaces are isolated by tenant ID at the application layer. Cross-tenant access is rejected by default at the data-access layer.
- Recruiter, hiring manager, interviewer, and admin roles are enforced server-side. Sensitive actions (mass exports, data deletion, billing changes) are audited.
- Internal access by our engineering team is granted on a least-privilege basis, requires SSO with hardware-key MFA, and is logged. Production-database access is broken-glass and ticket-gated.
- Secrets and API keys are stored in a managed vault and rotated on schedule. Short-lived credentials are preferred for backend services.
3. Application security
- Dependency scanning and automated security advisories run on every pull request.
- A security review is required for any change that touches authentication, authorisation, billing, or candidate data export.
- We run static analysis and container scanning in CI. Critical findings block deploys.
- Annual third-party penetration testing covers the application and APIs. A summary is shared with Customers on request under NDA.
4. Infrastructure
- Production runs on managed services in the India region. Subprocessors are listed at /subprocessors.
- We log application, infrastructure, and audit events to a tamper-evident store with restricted access.
- Monitoring and alerting cover availability, error rates, and anomalous data access patterns.
- Backups are taken daily with point-in-time recovery available for the production database.
5. AI safety
- Customer Data is not used to train foundational third-party models. We use enterprise terms with each model provider that disable training-on-input by default.
- Prompt and tool inputs are filtered and rate-limited. The AI interview agent has an allowlisted toolset and cannot move money or send external email outside the Customer's connected mailbox.
- AI outputs are advisory. Recruiters must approve hiring-impact decisions. The Platform is not designed for solely automated decision-making.
6. People
- All RecruitSphere personnel undergo background checks where permitted by law and sign confidentiality and IP assignment agreements.
- Security and privacy training is required on hire and annually thereafter.
- Access to Customer Data is granted only when needed for support and is automatically revoked when the role changes or the person leaves.
7. Incident response
- We maintain a documented incident response plan with named on-call roles, severity definitions, and Customer-notification runbooks.
- We will notify affected Customers without undue delay, and not later than 72 hours, after confirming a personal data breach.
- Post-incident reviews are conducted for all SEV-1 and SEV-2 events. Summaries are shared with affected Customers.
- To report a vulnerability, email security@recruitsphere.space. We commit to acknowledging reports within two business days and to a no-retaliation policy for good-faith research.
8. Compliance posture
RecruitSphere is built to support compliance with the Digital Personal Data Protection Act, 2023, and aligns its controls with ISO 27001 and SOC 2 principles. A formal SOC 2 Type II report is on our roadmap for the next 12 months.
Need to talk to a human
Reach our legal and privacy team at legal@recruitsphere.space. For data protection and DPDP Act requests, write to grievance@recruitsphere.space.