Security & compliance
Built for the audit.
Hiring data is some of the most sensitive data your company holds. Staffer’s security model is built for that reality, not retrofitted around it.
- GDPRCompliant
- SOC 2In progress
- ISO/IEC 27001In progress
- EU AI ActIn progress
GDPR compliant · SOC 2, ISO 27001 and EU AI Act in progress
Security
How we protect your data.
Built on enterprise-grade cloud infrastructure inside the EU.
Layered defenses across our code, dependencies, and supply chain.
Customer data is encrypted, kept inside the EU, and never used to train shared models.
Sign in with Microsoft, Google, or LinkedIn. Invite-only access. MFA enforced for staff; just-in-time employee access.
Every score has a reasoning trace. Bias-tested per rubric, quarterly. Designed to meet EU AI Act high-risk system requirements.
Every shortlist, outreach, and offer is gated to a named person. No automated hiring decisions, ever.
Certifications
Where we stand.
GDPR compliance is continuous and current today. SOC 2 Type II, ISO/IEC 27001, and the EU AI Act conformity assessment are underway — controls implemented and evidence being collected.
| Status | Standard | Scope | Timing |
|---|---|---|---|
| Compliant | GDPR | Articles 5–37 + DPIA | Continuous |
| In progress | SOC 2 Type II | Security, Availability, Confidentiality | Type I report targeted Q3 2026 |
| In progress | ISO/IEC 27001 | ISMS, full platform | Stage 1 audit Q4 2026 |
| In progress | EU AI Act | High-risk system, Annex III | Conformity assessment in progress, 2026 |
GDPR reports available today. SOC 2 / ISO 27001 evidence packages and the audit roadmap are shared under NDA. Email security@staffer.com →
Your data, your call
Delete my data.
You own your data. Under GDPR Article 17 and equivalent global rights, you can request deletion at any time — whether you’re a customer, a candidate, or someone whose profile we’ve indexed from public sources.
Quick request
Open a pre-formatted email and we’ll handle the rest.
- 01Email us at privacy@staffer.com from the address tied to your data — or include enough identifiers for us to verify your request.
- 02We acknowledge within 72 hours and verify your identity. No automated forms — a named human handles every request.
- 03Deletion within 30 days of verification across active systems; backups purged within 90 days. We send written confirmation when complete.
Questions, answered straight.
In AWS eu-west-1 with cross-region replication to eu-north-1. Customer data stays inside the EU by default; US residency is available on Enterprise.
If yours isn't here, ask us
Disclosure
Found something? We want to hear.
Email security@staffer.com with the subject [VULN]. We acknowledge within 24 hours, triage within 72.