For enterprises
Enterprise hiring and HR, on your terms

Identity and access
Your identity provider, your roles, your network
Single sign-on
OIDC and SAML 2.0 per organization on domains you verify, with just-in-time provisioning, an optional “SSO required” rule and a break-glass admin so a broken identity provider cannot lock you out.SCIM 2.0
Users and groups from your identity provider, with group-to-workspace-role mappings. Setup steps are documented for Microsoft Entra ID and Okta.Custom roles
Build roles from a catalogue of permissions and assign them per workspace membership.IP allow-lists
IPv4 and IPv6 ranges per organization with lock-out safeguards, plus a separate list for each agency client portal.Two-factor sign-in
Optional TOTP two-factor authentication for people who sign in with a password.Every change audited
Administrative changes are audit events in your organization’s hash-chained audit trail.
Data and keys
Your data, your keys, your region
Customer-managed keys
Stored secrets are sealed with envelope encryption: a data key per organization, wrapped by a key in Azure Key Vault. Bring your own Key Vault key, and revoking it makes your organization’s encrypted values unreadable.Dedicated database
The dedicated-database tier keeps your workspace data in its own PostgreSQL database with the same schema, set up by our operators. Requests never fall through to the shared database; identity, audit and billing data stay in the shared control plane.Data residency
Your organization’s region decides where new files are stored and which model endpoint serves you. The EU (Sweden Central) is the default; other regions are available once provisioned. Files are never written to another region, and AI requests fall back to rules instead of leaving it.Business units
One organization with a workspace per business unit. Organization owners and admins reach every workspace; everyone else reaches only the workspaces they are members of.
Isolation tiers
Pooled or dedicated
| What you get | Pooled (default) | Dedicated database |
|---|---|---|
| Workspace data | Shared PostgreSQL database, separated by workspace with row-level security | Your own PostgreSQL database with the same schema |
| Application scoping of every query | Yes | Yes |
| Identity, audit and billing data | Shared control plane | Shared control plane |
| Candidate-facing flows | Shared database | Shared database |
| Set up by | Automatic | HireGenix operators |
Open to your agents
Connect your own agents, safely
OAuth 2.1
An authorization server for external agents: authorization code with PKCE, client credentials, rotating refresh tokens and short-lived, scoped access tokens.MCP
Your agents call HireGenix tools over MCP. Tokens are checked on every call, and write tools return a pending approval instead of changing data.A2A
The AI CHRO is available as an A2A agent. Its recommendations to your agents become approval requests in HireGenix.
Questions
Enterprise questions
Yes. Single sign-on works with OIDC and SAML 2.0 identity providers on domains you verify with a DNS record, and SCIM 2.0 keeps users and groups in sync. Setup steps are documented for Microsoft Entra ID and Okta.
Yes, for stored secrets such as integration credentials, single sign-on secrets and calendar tokens: they are sealed with a data key per organization that is wrapped by your own Azure Key Vault key, and revoking your key makes them unreadable.
Your organization’s region decides where new files are stored and which AI model endpoint serves you: the EU (Sweden Central) by default, or another region once it is provisioned for you. Email and SMS delivery, browser uploads, People Ops documents and realtime voice are not regional yet.
Only within the autonomy you set. Adverse decisions wait for a person by default, offers, integrity outcomes and biometric decisions always do, and external agents that connect over MCP or A2A can only create approval requests for changes.
Not yet. Our SOC 2 readiness checklist tracks the controls in place and the gaps we are closing before an examination. The trust center lists every document in our compliance pack.
Bring your security and HR teams to the demo
We will go through identity, keys, residency and the approvals model with the people who need to sign off.