1. Hosting and data residency

2. Encryption

At rest

In transit

3. Access controls

4. Audit logging

5. AI and machine learning policy

6. Certifications and compliance

Honest status: SmartHire itself is not yet SOC 2 or ISO 27001 certified. We plan to pursue SOC 2 Type II as the company matures. Ask us for the current roadmap.

The underlying AWS infrastructure we build on is independently certified to a wide range of standards, including SOC 1 / SOC 2 / SOC 3, ISO 27001, ISO 27017, ISO 27018, HIPAA, PCI-DSS, and GDPR. AWS publishes its full attestation catalog at aws.amazon.com/compliance/programs.

What that means in practice: the underlying hosting, encryption, physical security, and access-control primitives are already independently audited. SmartHire builds its application-level controls on top of that foundation. Our own SmartHire-level certification will attest to the way we use those primitives.

7. Vulnerability disclosure

If you believe you've found a security issue, please report it to security@smarthire.chat. Include enough detail to reproduce it. We will:

Please do not run automated scanners against the production environment. Test against your own tenant, and do not access data belonging to other customers.

8. Incident response

9. Business continuity

10. Vendor management

Every sub-processor is listed at /subprocessors/ with its purpose, region, and transfer mechanism. Changes trigger a 30-day notice to customers.

11. Where to go next