Security & compliance
Built for the audit.
Hiring data is some of the most sensitive data your company holds. Staffer’s security model is built for that reality, not retrofitted around it.
- GDPRCompliant
- SOC 2Planned
- EU AI ActIn progress
GDPR compliant · EU AI Act in progress · SOC 2 audit planned
Security
How we protect your data.
Application, database, search index and file storage all run in the EU. One background-job provider runs in the US, under Standard Contractual Clauses.
Capability-based authorization, not roles: every mutation checks a typed capability on the server. Static analysis and dependency review on every pull request.
TLS 1.2+ in transit, provider encryption at rest, and AES-256-GCM applied in the application to tokens and compliance content. Never used to train any model.
Sign in with Microsoft, Google, or LinkedIn. Invite-only access. Every sign-in and privileged-access event lands in an append-only log.
Every score is written to an immutable evaluation record with its criteria, model and inputs, so any decision can be explained after the fact.
Every shortlist, outreach, and offer is gated to a named person. The agent recommends; it never decides. No automated hiring decisions, ever.
Certifications
Where we stand.
GDPR compliance is continuous and current today. The EU AI Act work is partly shipped — the record-keeping, transparency and human-oversight obligations are live, and the monitoring ones are not built yet. A SOC 2 Type 1 audit is scoped and planned for after launch; we would rather say that than call it underway.
| Status | Standard | Scope | Timing |
|---|---|---|---|
| Compliant | GDPR | Controller and processor obligations, DPA and sub-processor register | Continuous |
| Planned | SOC 2 Type 1 | Security, Availability, Confidentiality | Audit planned post-launch |
| In progress | EU AI Act | High-risk system, Annex III §4 | Architecture aligned ahead of enforcement |
Until a formal report exists we share our current security posture and control descriptions under NDA. The NDA and the posture document come back within 3 business days. Email compliance@staffer.com →
Your data, your call
Delete my data.
You own your data. Under GDPR Article 17 and equivalent global rights, you can request deletion at any time — whether you’re a customer, a candidate, or someone whose profile we’ve indexed from public sources.
Quick request
Open a pre-formatted email and we’ll handle the rest.
- 01Email us at privacy@staffer.com from the address tied to your data — or include enough identifiers for us to verify your request.
- 02We acknowledge within 72 hours and verify your identity, so that nobody can delete your data but you.
- 03Hidden immediately, destroyed after 30 days — your profile leaves search, the portal and public listings the moment we act. The data itself goes at the end of a window you can still change your mind in, and backups age out within 30 days after that.
- 04Your hiring record is anonymised, not deleted where an employer has to keep proof of how a decision was reached. Everything identifying goes — name, contact details, interview transcripts and recordings. The stage history and criterion scores stay, linked to nobody.
Questions, answered straight.
In the EU. The database is Neon in eu-central-1, the corpus and audit trail are in ClickHouse Cloud EU, the search index is Turbopuffer EU, files are in Google Cloud Storage europe-west4, and the application itself runs in Frankfurt. AI inference is EU-resident too: prompts go to an EU in-region endpoint that only routes to providers operating there. Background job orchestration is the one exception — that provider has no EU region and is covered by Standard Contractual Clauses. Our CDN is global by design, so a request enters at the location nearest you before reaching the EU.
If yours isn't here, ask us
Disclosure
Found something? We want to hear.
Email security@staffer.com with the subject [VULN]. We acknowledge within 24 hours, triage within 72.