Our Security Architecture
Recruitment operations process highly confidential personnel and corporate information. AIRecruitEngine is designed around defense-in-depth principles across every infrastructure layer:
1. Cryptographic Controls & Data Encryption
- Data in Transit: All web and API traffic is encrypted using TLS 1.3 with modern cipher suites and HTTP Strict Transport Security (HSTS).
- Data at Rest: Candidate records, interview transcripts, and ATS data are encrypted using industry-standard AES-256 with managed key rotation.
- Zero Model Training on Customer Requisitions: Customer data is isolated and is never used to train public or shared foundation models.
2. Identity, Authentication & Access Governance
- Enterprise SSO: Full support for SAML 2.0 and OIDC authentication protocols with Okta, Microsoft Entra ID (Azure AD), Google Workspace, and Ping Identity.
- Automated Provisioning (SCIM): SCIM 2.0 support ensures instant account creation, role updates, and immediate access revocation upon employee offboarding.
- Role-Based Access Control (RBAC): Granular permissions separate the capabilities of Hiring Managers, Technical Interviewers, Recruiters, and HR Executives.
3. Data Residency & Regional Isolation
To satisfy international compliance and data sovereignty mandates (including GDPR and regional privacy laws), customers can specify data residency within US or EU cloud availability zones.
4. Continuous Vulnerability Management & Audit Logging
- Immutable Audit Trails: Every candidate score modification, interview view, and export action is timestamped and logged in append-only audit telemetry.
- Automated Dependency Scanning: Continuous static and dynamic application security testing (SAST/DAST) across all software repositories.
- Penetration Testing: Regular third-party penetration tests evaluate web applications, API endpoints, and cloud infrastructure.