Trust & security
Security & Trust
HCIA is built on a foundation of transparency, security, and compliance. Every decision — technical and AI — is explainable and auditable.
How we protect your data and candidates
PII redaction before AI
Names, emails, phone numbers, and other identifiers are stripped from CV content before any LLM call. Candidates are scored on skills and experience — not identity.
Built-in bias detection
Shortlist composition and score distributions are monitored for anomalies across protected characteristic proxies. Alerts surface automatically when statistical deviations are detected.
Multi-tenant isolation
Every workspace is fully isolated at the data layer. One tenant can never access another's candidates, jobs, or scores.
Audit trail
Every AI decision, score override, and stage change is logged with a timestamp and user identity. Suitable for compliance review.
GDPR compliance
Data processing agreements, configurable retention policies, and one-click candidate data deletion. Your GDPR obligations are covered.
SSO & access control
Microsoft Entra ID / Azure AD SSO for Enterprise. Role-based access control lets you limit who can view scores, export data, or manage roles.
PII protection
See how PII gets redacted before AI sees it
Before any CV reaches an AI model, names, emails, phone numbers, and other identifiers are stripped — so candidates are scored on merit, not identity.
Scroll to see PII redaction in action
Responsible AI commitments
- GDPR compliant data processing
Data processing agreements available. All personal data stays within your configured region. Candidate deletion requests completed within 30 days. Learn more GDPR compliant data processing
- Explainable AI decisions
Every fit score is backed by evidence extracted from the candidate's own CV. No black-box outputs — every decision can be audited and defended.
- Bias monitoring alerts
Automated statistical monitoring flags shortlist composition anomalies. Recruiters receive in-app alerts and can review or override scoring.
- PII redaction
Names, contacts, and other identifying fields are stripped before LLM inference. AI scores are based on skills and experience, not identity.
- SOC 2 Type IIComing soon
Independent audit of our security, availability, and confidentiality controls. SOC 2 Type II certification is in progress — expected completion Q4 2026.
- ISO 27001Coming soon
Internationally recognised standard for information security management. Our ISMS implementation and certification process is underway — target completion Q4 2026.
Enterprise-grade security, transparent by design.
SOC 2 Type II certified. GDPR compliant. Your data stays yours.