Security and privacy at Asendia AI
Helping staffing agencies hire faster starts with protecting the candidate and client data they trust us with. Security is built into every layer of the platform that powers Sarah, our AI recruiter.
A security program built on four principles
Our governance framework sets the policies and controls that keep recruitment data confidential, available, and intact.
Least privilege
Access to candidate data, interview recordings, and models is granted strictly on legitimate business need.
Defense in depth
Multiple, independent layers of controls protect every part of the platform — no single failure exposes data.
Consistent controls
The same security standards apply across every environment, integration, and supported language.
Continuous improvement
We iterate on our program continuously as threats, regulations, and our platform evolve.
Compliant with the regulations that matter for recruitment
Asendia AI is built to meet the data-protection standards staffing agencies rely on, and we're happy to share documentation on request.
GDPR
Fully compliant with EU General Data Protection Regulation.
HIPAA
Safeguards for protected health information.
Encrypted end to end, at every layer
Interview recordings, transcripts, candidate assessments, and model outputs are protected in transit and at rest.
Data at rest
Data in transit
Secret management
Protecting Sarah and every interview she runs
Sarah is our proprietary AI recruiter. We safeguard the models behind her and the integrity of every screening she conducts.
Model security
- Proprietary algorithms and model weights encrypted and access-controlled
- Locked-down deployment pipeline for model updates
- Regular security audits of AI inference pipelines
- Monitoring for model poisoning and adversarial attacks
Interview integrity
- Fraud detection guards against cheating and outside AI assistance
- Tab-switching, script usage, and external tool detection
- Behavioral analysis to confirm authentic candidate responses
- Immutable audit trails for every interview interaction
Security baked into how we build
Our Secure Development Lifecycle tests the platform continuously — from every pull request to annual third-party assessments.
Penetration testing
Vulnerability scanning
- SAST on every pull request and continuously
- Software composition analysis across our supply chain
- Malicious-dependency scanning before code ships
- DAST against running apps and API endpoints
- Continuous external attack-surface management
Hardened from the endpoint to the ATS
The controls that protect our team, our network, and every integration we sync data through.
Endpoint protection
- Centrally managed corporate devices
- Mobile Device Management everywhere
- Anti-malware on every endpoint
- 24/7/365 monitoring
ATS integration security
- Secure APIs across 50+ ATS platforms
- OAuth 2.0 and token-based auth
- Encryption during every sync
- Granular data-access permissions
Identity & access
- Okta-powered identity management
- WebAuthn strong authentication
- Role-based access controls
- Extra controls for recruitment data
Vendor security
- Risk-based vendor reviews
- Assessed for data access and impact
- Residual-risk approval decisions
- Ongoing partner monitoring
Ready for incidents, built to stay available
Incident response
- Dedicated incident response team
- 24/7 monitoring and alerting
- Defined escalation procedures
- Regular response testing and post-incident review
Business continuity
- Backup and recovery procedures
- Disaster recovery planning
- Geographic redundancy and failover
- Regular backup testing and validation
Trustworthy stewards of candidate data
Data privacy is a first-class priority. We continuously track regulatory and emerging frameworks — with special focus on recruitment and AI ethics.
Cross-border transfers
Evolving compliance
Your rights
Security you can verify, not just take our word for
Reviewing Asendia AI for your staffing agency? Our team will walk you through our controls and share the documentation your security review needs.