Skip to content

Trust & security

Security & Trust

HCIA is built on a foundation of transparency, security, and compliance. Every decision — technical and AI — is explainable and auditable.

How we protect your data and candidates

  • PII redaction before AI

    Names, emails, phone numbers, and other identifiers are stripped from CV content before any LLM call. Candidates are scored on skills and experience — not identity.

  • Built-in bias detection

    Shortlist composition and score distributions are monitored for anomalies across protected characteristic proxies. Alerts surface automatically when statistical deviations are detected.

  • Multi-tenant isolation

    Every workspace is fully isolated at the data layer. One tenant can never access another's candidates, jobs, or scores.

  • Audit trail

    Every AI decision, score override, and stage change is logged with a timestamp and user identity. Suitable for compliance review.

  • GDPR compliance

    Data processing agreements, configurable retention policies, and one-click candidate data deletion. Your GDPR obligations are covered.

  • SSO & access control

    Microsoft Entra ID / Azure AD SSO for Enterprise. Role-based access control lets you limit who can view scores, export data, or manage roles.

PII protection

See how PII gets redacted before AI sees it

Before any CV reaches an AI model, names, emails, phone numbers, and other identifiers are stripped — so candidates are scored on merit, not identity.

CONFIDENTIAL — PII REDACTION REPORTSTAGE:: PENDING
Pre-processing pipeline

Scroll to see PII redaction in action

Responsible AI commitments

  • GDPR compliant data processing

    Data processing agreements available. All personal data stays within your configured region. Candidate deletion requests completed within 30 days. Learn more GDPR compliant data processing

  • Explainable AI decisions

    Every fit score is backed by evidence extracted from the candidate's own CV. No black-box outputs — every decision can be audited and defended.

  • Bias monitoring alerts

    Automated statistical monitoring flags shortlist composition anomalies. Recruiters receive in-app alerts and can review or override scoring.

  • PII redaction

    Names, contacts, and other identifying fields are stripped before LLM inference. AI scores are based on skills and experience, not identity.

  • SOC 2 Type II
    Coming soon

    Independent audit of our security, availability, and confidentiality controls. SOC 2 Type II certification is in progress — expected completion Q4 2026.

  • ISO 27001
    Coming soon

    Internationally recognised standard for information security management. Our ISMS implementation and certification process is underway — target completion Q4 2026.

Enterprise-grade security, transparent by design.

SOC 2 Type II certified. GDPR compliant. Your data stays yours.