Security & compliance

Built for the audit.

Hiring data is some of the most sensitive data your company holds. Staffer’s security model is built for that reality, not retrofitted around it.

  • GDPR — compliant
    GDPRCompliant
  • SOC 2 — planned
    SOC 2Planned
  • EU AI Act — in progress
    EU AI ActIn progress

GDPR compliant · EU AI Act in progress · SOC 2 audit planned

Security

How we protect your data.

01Infrastructure

Application, database, search index and file storage all run in the EU. One background-job provider runs in the US, under Standard Contractual Clauses.

02Application security

Capability-based authorization, not roles: every mutation checks a typed capability on the server. Static analysis and dependency review on every pull request.

03Data protection

TLS 1.2+ in transit, provider encryption at rest, and AES-256-GCM applied in the application to tokens and compliance content. Never used to train any model.

04Identity & access

Sign in with Microsoft, Google, or LinkedIn. Invite-only access. Every sign-in and privileged-access event lands in an append-only log.

05AI safety

Every score is written to an immutable evaluation record with its criteria, model and inputs, so any decision can be explained after the fact.

06Human in the loop

Every shortlist, outreach, and offer is gated to a named person. The agent recommends; it never decides. No automated hiring decisions, ever.

Certifications

Where we stand.

GDPR compliance is continuous and current today. The EU AI Act work is partly shipped — the record-keeping, transparency and human-oversight obligations are live, and the monitoring ones are not built yet. A SOC 2 Type 1 audit is scoped and planned for after launch; we would rather say that than call it underway.

StatusStandardScopeTiming
CompliantGDPRController and processor obligations, DPA and sub-processor registerContinuous
PlannedSOC 2 Type 1Security, Availability, ConfidentialityAudit planned post-launch
In progressEU AI ActHigh-risk system, Annex III §4Architecture aligned ahead of enforcement

Until a formal report exists we share our current security posture and control descriptions under NDA. The NDA and the posture document come back within 3 business days. Email compliance@staffer.com →

Your data, your call

Delete my data.

You own your data. Under GDPR Article 17 and equivalent global rights, you can request deletion at any time — whether you’re a customer, a candidate, or someone whose profile we’ve indexed from public sources.

Quick request

Open a pre-formatted email and we’ll handle the rest.

  1. 01Email us at privacy@staffer.com from the address tied to your data — or include enough identifiers for us to verify your request.
  2. 02We acknowledge within 72 hours and verify your identity, so that nobody can delete your data but you.
  3. 03Hidden immediately, destroyed after 30 days — your profile leaves search, the portal and public listings the moment we act. The data itself goes at the end of a window you can still change your mind in, and backups age out within 30 days after that.
  4. 04Your hiring record is anonymised, not deleted where an employer has to keep proof of how a decision was reached. Everything identifying goes — name, contact details, interview transcripts and recordings. The stage history and criterion scores stay, linked to nobody.

Questions, answered straight.

In the EU. The database is Neon in eu-central-1, the corpus and audit trail are in ClickHouse Cloud EU, the search index is Turbopuffer EU, files are in Google Cloud Storage europe-west4, and the application itself runs in Frankfurt. AI inference is EU-resident too: prompts go to an EU in-region endpoint that only routes to providers operating there. Background job orchestration is the one exception — that provider has no EU region and is covered by Standard Contractual Clauses. Our CDN is global by design, so a request enters at the location nearest you before reaching the EU.

If yours isn't here, ask us

Disclosure

Found something? We want to hear.

Email security@staffer.com with the subject [VULN]. We acknowledge within 24 hours, triage within 72.