1. Overview
HireX processes business recruiting data, including customer account details, candidate profiles, resumes, interview answers, evaluations, files, offer workflows, and usage records. Our security approach focuses on protecting confidentiality, integrity, and availability across those workflows.
This page summarizes the safeguards HireX uses or expects to use in operating the service. It is not a contractual commitment by itself; customer agreements, data-processing terms, and security exhibits should define binding obligations.
2. Data protection
Candidate and recruiting data is separated by organization and accessed through authenticated, role-based workflows.
The service supports retention configuration, candidate export, and candidate erasure workflows to help customers manage privacy obligations.
File access is controlled through signed access URLs and application authorization checks.
Sensitive actions and security-relevant events should be recorded through operational logs and audit records.
Based on the current implementation, HireX uses a PostgreSQL-compatible database, Redis-backed queues and caching, S3-compatible object storage for files, SMTP email delivery, Stripe for billing workflows, and OpenAI for selected AI-assisted recruiting features. Production provider details may vary by deployment environment.
3. Access control
HireX uses tenant membership, roles, permissions, and secure authentication flows to limit access to customer data. Product features can restrict administrative actions, billing changes, vacancy management, candidate visibility, and other sensitive operations.
Multi-factor authentication is available on paid plans where enabled. Customers should require MFA for administrators and other users with broad access to candidate or organization data.
4. Application security
Encrypted connections are used for browser-to-service traffic.
Password credentials are protected using password hashing rather than plaintext storage.
Authentication cookies, token rotation, CSRF protections, and request validation are used to reduce common web risks.
Customer file access and candidate portal flows are protected by authorization checks and time-limited access mechanisms where appropriate.
5. AI processing
HireX uses AI-assisted features for recruiting workflows, such as resume parsing, task and question generation, transcription, answer evaluation, candidate summaries, embeddings, and matching. These features may involve sending selected recruiting content to AI service providers.
AI output is intended to assist hiring teams, not replace human decision-making. Customers remain responsible for employment decisions, notices, review processes, and legal bases required for their hiring activity.
6. Availability and resilience
HireX should be operated with production monitoring, backups, recovery procedures, and change-management practices appropriate for a recruiting SaaS product. The exact uptime commitments, support response times, and recovery targets should be defined in customer agreements where applicable.
Until formal service-level commitments are published, uptime, backup frequency, recovery targets, and support response times should be treated as operational practices or contract-specific commitments rather than public guarantees.
7. Incident response
HireX should maintain an incident-response process for detecting, investigating, containing, and communicating security incidents. If a confirmed incident affects personal information, HireX should notify affected customers according to contractual and legal requirements.
Unless a customer agreement provides a specific notification timeline, HireX should provide required security and privacy incident notices without undue delay and in accordance with applicable law.
8. Compliance status
GDPR and data processing
HireX is generally a processor for candidate and recruiting data handled on behalf of hiring organizations, and a controller for account, billing, security, support, website, and service operations data. Customer contracts should include appropriate data-processing terms where GDPR, UK GDPR, or similar laws apply.
SOC 2 Type II and ISO/IEC 27001
HireX does not currently make a public claim of SOC 2 Type II compliance or ISO/IEC 27001 certification on this page. Those claims should only be added after an independent audit or accredited certification is complete and verifiable.
If HireX later completes an assurance program, this page should be updated with the report or certificate scope, audit period, auditor or certification body, and the process customers should use to request access.
9. Customer responsibilities
Customers are responsible for configuring HireX appropriately for their organization, granting least-privilege access, removing users who no longer need access, using strong authentication, configuring retention settings, and providing legally required candidate notices and consent flows.
10. Contact
For security questions, customers should use the support or account channel provided by their HireX representative.
For privacy details, see the Privacy Policy.