Trust & Security

Security and privacy at Asendia AI

Helping staffing agencies hire faster starts with protecting the candidate and client data they trust us with. Security is built into every layer of the platform that powers Sarah, our AI recruiter.

GDPRHIPAA
Governance

A security program built on four principles

Our governance framework sets the policies and controls that keep recruitment data confidential, available, and intact.

01

Least privilege

Access to candidate data, interview recordings, and models is granted strictly on legitimate business need.

02

Defense in depth

Multiple, independent layers of controls protect every part of the platform — no single failure exposes data.

03

Consistent controls

The same security standards apply across every environment, integration, and supported language.

04

Continuous improvement

We iterate on our program continuously as threats, regulations, and our platform evolve.

Compliance

Compliant with the regulations that matter for recruitment

Asendia AI is built to meet the data-protection standards staffing agencies rely on, and we're happy to share documentation on request.

GDPR

Fully compliant with EU General Data Protection Regulation.

HIPAA

Safeguards for protected health information.

Data protection

Encrypted end to end, at every layer

Interview recordings, transcripts, candidate assessments, and model outputs are protected in transit and at rest.

Data at rest

Every datastore and S3 bucket holding recruitment data is encrypted at rest. Sensitive fields — transcripts, candidate responses, and model outputs — get field-level encryption, so neither physical nor logical database access is enough to read them.

Data in transit

We enforce TLS 1.2+ everywhere data crosses a network, with HSTS to harden it further. TLS keys and certificates are managed by AWS and served through Application Load Balancers across every supported language.

Secret management

Encryption keys live in AWS KMS, backed by hardware security modules that no Asendia or Amazon employee can read directly. Application secrets are held in AWS Secrets Manager and Parameter Store with tightly scoped access.
AI integrity

Protecting Sarah and every interview she runs

Sarah is our proprietary AI recruiter. We safeguard the models behind her and the integrity of every screening she conducts.

Model security

  • Proprietary algorithms and model weights encrypted and access-controlled
  • Locked-down deployment pipeline for model updates
  • Regular security audits of AI inference pipelines
  • Monitoring for model poisoning and adversarial attacks

Interview integrity

  • Fraud detection guards against cheating and outside AI assistance
  • Tab-switching, script usage, and external tool detection
  • Behavioral analysis to confirm authentic candidate responses
  • Immutable audit trails for every interview interaction
Product security

Security baked into how we build

Our Secure Development Lifecycle tests the platform continuously — from every pull request to annual third-party assessments.

Penetration testing

We engage leading penetration-testing firms at least annually, with the entire platform and cloud infrastructure in scope — Sarah's algorithms, fraud detection, multilingual pipelines, and our 50+ ATS integrations. Testers get full source-code access, and summary reports are available to enterprise customers on request.

Vulnerability scanning

  • SAST on every pull request and continuously
  • Software composition analysis across our supply chain
  • Malicious-dependency scanning before code ships
  • DAST against running apps and API endpoints
  • Continuous external attack-surface management
Enterprise security

Hardened from the endpoint to the ATS

The controls that protect our team, our network, and every integration we sync data through.

Endpoint protection

  • Centrally managed corporate devices
  • Mobile Device Management everywhere
  • Anti-malware on every endpoint
  • 24/7/365 monitoring

ATS integration security

  • Secure APIs across 50+ ATS platforms
  • OAuth 2.0 and token-based auth
  • Encryption during every sync
  • Granular data-access permissions

Identity & access

  • Okta-powered identity management
  • WebAuthn strong authentication
  • Role-based access controls
  • Extra controls for recruitment data

Vendor security

  • Risk-based vendor reviews
  • Assessed for data access and impact
  • Residual-risk approval decisions
  • Ongoing partner monitoring
Resilience

Ready for incidents, built to stay available

Incident response

  • Dedicated incident response team
  • 24/7 monitoring and alerting
  • Defined escalation procedures
  • Regular response testing and post-incident review

Business continuity

  • Backup and recovery procedures
  • Disaster recovery planning
  • Geographic redundancy and failover
  • Regular backup testing and validation
Data privacy

Trustworthy stewards of candidate data

Data privacy is a first-class priority. We continuously track regulatory and emerging frameworks — with special focus on recruitment and AI ethics.

Cross-border transfers

Standard Contractual Clauses and appropriate safeguards govern cross-border data transfers, keeping international recruitment compliant with GDPR and current data-transfer standards.

Evolving compliance

We evaluate updates to regulations and emerging AI frameworks continuously, evolving our program to stay ahead of recruitment-industry requirements.

Your rights

Candidates and clients can exercise their data rights, and we honor deletion and access requests in line with GDPR and CCPA.

Security you can verify, not just take our word for

Reviewing Asendia AI for your staffing agency? Our team will walk you through our controls and share the documentation your security review needs.