When candidates share their professional history and companies share hiring criteria, they trust us with sensitive data. Security is built into every layer of AIHire — not bolted on afterwards.
ENCRYPTED AT REST
GDPR COMPLIANT
CCPA COMPLIANT
AES-256 ENCRYPTED
End-to-End Encryption
All data is encrypted in transit with TLS and at rest with AES-256 by our infrastructure providers. Session recordings are stored in private object storage and are reachable only through short-lived signed URLs, never as public objects.
Zero-Trust Architecture
Every internal service call is authenticated regardless of network location. No component is implicitly trusted — access is granted based on verified identity, not network proximity.
Built on Audited Infrastructure
AIHire runs on SOC 2 audited infrastructure providers (AWS, Supabase, Vercel). AIHire itself does not currently hold its own SOC 2 attestation, and we will say so plainly rather than imply otherwise. Our security documentation and sub-processor attestations are available to customers on request under NDA.
Role-Based Access Control
RBAC enforced at database, API, and UI levels simultaneously. Audit logs capture session access, authentication and administrative actions with user identity and timestamp. Tenant data fully isolated via row-level security.
GDPR & CCPA — Your Rights
Deletion requests processed in 30 days
Data portability exports in JSON
No personal data sold to third parties
Consent records stored and auditable
Standard DPA available for all customers
Responsible disclosure programme open
Security concerns? Report them to security@aihire.io — we acknowledge all reports within 24 hours.