Trust center
Security and trust, built into the platform
Tenant isolation
Two walls between every workspace
Wall one: the application
Every route and the Agents API scope each query to the active workspace. Each browser tab works in one workspace, and a request for a workspace you may not enter never falls back to another one.Wall two: the database
PostgreSQL row-level security makes the database itself refuse rows of other workspaces, so a forgotten filter returns nothing.Tested on every pull request
An isolation suite calls every route with every role and another tenant’s ids, checks row-level security on every protected table, hands agents another workspace’s ids through a deliberately malicious fake model and plants canary rows for every tenant.Strict silos for agencies
Agency clients can be strict silos, so the people sourced for one client stay with that client.
Encryption
Encrypted in transit, at rest and by key
In transit
TLS everywhere, with HSTS and strict security headers.At rest
Azure storage encryption. Files sit in private containers behind short-lived, read-only links.Envelope encryption
Stored secrets are sealed with AES-256-GCM using a data key per organization, wrapped by an Azure Key Vault key. SCIM tokens and OAuth client secrets are kept only as hashes.Customer-managed keys
Use your own Key Vault key. Revoking it makes your organization’s encrypted values unreadable.
Identity and access
Access that follows your rules
Single sign-on
OIDC and SAML 2.0 with your identity provider, on domains you verify.SCIM 2.0
Users and groups provisioned from your identity provider, mapped to workspace roles.Two-factor sign-in
Optional TOTP two-factor authentication for password sign-in.Roles and custom roles
Role-based access per workspace, and custom roles built from a catalogue of permissions.IP allow-lists
Limit access to your network ranges, with safeguards against locking yourself out.Audit trail
An append-only log with one hash chain per organization, verified daily and exportable.
Data residency
Files and AI calls stay in your region
Not regional yet
- People Ops document storage
- Browser uploads
- Realtime voice and transcription
- Email and SMS through Azure Communication Services, which stores data in the US
Privacy
Privacy by design
Consent first
Explicit consent before any monitoring, a separate biometric release and a non-biometric alternative.Data-subject requests
Data exports are emailed as a signed download link; on a deletion request, content is anonymised immediately.Retention jobs
Scheduled jobs delete proctoring data and videos, integrity records and clips, consent records and identity checks, onboarding documents and helpdesk questions when their retention ends.
Responsible AI
AI that people can supervise
No emotion recognition
Nothing infers emotion, stress, facial expressions or deception, and there are no AI-text detectors.A legal floor in code
Offers, integrity outcomes, biometric decisions and fraud-case actions never run above “approval required”.Identity-blind screening
Screening leaves out name, email, phone and photo, and critics reject rationales that mention protected characteristics.Fairness monitoring
Fairness figures use only voluntary self-identification, which is never shown to recruiters or AI screening and never used in decisions.Injection defences
Untrusted text is kept apart from agent instructions, injection attempts are detected and personal information is masked in agent traces.AI-use notices
Candidates are told when AI is used, and integrity outcomes come with reasons and an appeal.
Compliance documents
Documentation for your security and legal review
EU AI Act technical documentation
HireGenix described as a high-risk AI system: purpose, data, human oversight and the open items before a conformity assessment.
Bias audit
How adverse impact is measured with the four-fifths rule, and what is still missing for a complete audit.
DPDP records of processing
Records of processing and the notice inventory under India’s DPDP Act, which also serve as GDPR Article 30 records.
Retention schedule
What is deleted automatically and when, and what is not automated yet.
SOC 2 readiness checklist
The controls in place and the gaps we are closing before a SOC 2 examination.
Private networking runbook
Our plan for private endpoints and a web application firewall, which has not been carried out yet.
Responsible disclosure
Report a vulnerability
Questions
Security questions
Isolation is enforced twice: by the application, which scopes every query to the active workspace, and by PostgreSQL row-level security in the database. An isolation suite tests both on every pull request.
Stored secrets: integration credentials, single sign-on secrets and keys, OAuth signing keys, calendar tokens, job-board keys, AI configuration keys and identity-verification references. Other data is encrypted at rest by Azure storage encryption.
Not yet. Our SOC 2 readiness checklist tracks the controls in place and the gaps we are closing before an examination.
Yes. A data export is emailed as a signed download link, and on a deletion request the content is anonymised immediately.
Email support@myhiregenix.ai with a subject line that starts with [SECURITY], and do not open a public issue. We confirm the report, fix it and tell you when the fix is live.
Questions from your security team?
Book a call and we will go through isolation, keys, residency and our compliance documents with them.