SECURITY AND PRIVACY

Security and data privacy

The candidate personal data you store in 100Hires stays encrypted, hosted in the EU or the US to match where you operate, and governed by a data processing agreement you can hand straight to your security and legal teams.

100Hires GDPR settings showing candidate data retention and consent controls

Your applicant tracking system holds some of the most sensitive data your company touches: resumes, contact details, interview notes, evaluations, and messages for every person who applies.

When IT or a security reviewer asks how that data is protected, you need a straight answer, not a sales pitch.

This page is that answer. You are the data controller for your candidate data and 100Hires is your processor, so the controls below exist to support your own obligations to candidates.

The full Security FAQ and a GDPR data processing agreement are available on request, and everything here maps to what your reviewers actually ask about.

Security at a glance
Area How 100Hires handles it
Encryption AES-256 at rest and TLS 1.2+ in transit, on every application and API connection
Data residency EU data hosted in Germany; US, Canadian and rest-of-world data hosted on AWS in the United States
Access control SSH-key-only servers, MFA on every sensitive system, role-based access, quarterly access reviews
Data ownership You own everything you upload, and 100Hires never trains AI models on your data
Privacy compliance GDPR data processor with a DPA on request; controls support PIPEDA, Quebec Law 25, and CASL
Certifications AWS hosting is SOC 2 Type II and ISO 27001 certified; Hetzner data centers are ISO 27001 certified; 100Hires SOC 2 Type II attestation is in progress
Breach notice Customer notification within 72 hours of a confirmed breach, with a detailed report inside 7 days
Data deletion Full, irreversible deletion after a six-month post-cancellation window, with a certificate of destruction on request

Your data is encrypted everywhere it lives

Candidate data is encrypted in transit with TLS 1.2 or higher across all network communication, and encrypted at rest with AES-256 in the database. Every web service runs on a valid SSL certificate, and every API and application connection is encrypted.

Email sent from your account is authenticated with DKIM, SPF, and DMARC, which makes candidate messages far less likely to be spoofed.

Your data is hosted in the EU or the US

Where your candidate data physically lives is decided by your primary location. EU customers are hosted in Hetzner data centers in Germany, which publish ISO 27001 certification.

Customers in the US, Canada, and the rest of the world are hosted on Amazon Web Services in the United States, which is SOC 2 Type II and ISO 27001 certified.

Both locations encrypt data in transit and at rest. We say this plainly because it matters for your own assessment: for Canadian customers, candidate data is hosted in the US, which is the detail a Quebec Law 25 privacy impact assessment turns on.

If you need an input document for that assessment, we provide one on request.

You own your data, and we never train AI on it

You keep full ownership of everything you upload or generate in 100Hires: candidate profiles, resumes, notes, evaluations, and messages. We process that data only to run the service for you. We do not sell it, license it, or hand it to anyone for marketing or analytics.

100Hires does not train its own AI models on your data.

When a feature like AI Score, the AI Copilot, or the AI Email Composer sends data to an AI provider, we use paid API tiers under commercial terms where the provider contractually commits not to train its models on your prompts or content.

If your policy or your jurisdiction does not allow third-party AI at all, you can turn every AI feature off for the whole account in one place.

What you control in 100Hires
What you control How it works in 100Hires
Where data lives Your account is hosted in the EU or the US based on your primary location
AI on or off Turn AI Score, the AI Copilot, and the AI Email Composer off for the whole account at any time
How long data is kept Set candidate data retention from 1 to 60 months, with optional automatic deletion when it expires
Consent Track consent per candidate with a full audit trail and automatic renewal requests - you choose and document your lawful basis
Erasure Remove a candidate profile and all of its data for a right-to-be-forgotten request
Export Export candidate data from the Candidates page at any time, including the post-cancellation retention window
Your DPA Request a GDPR data processing agreement, including Standard Contractual Clauses, from privacy@100hires.com

Locked-down access, monitored in real time

Servers accept SSH key authentication only, with password login disabled, and keys are rotated when staff change. Multi-factor authentication is required on every security-sensitive system, including administrative access, customer-data repositories, and any vendor connection.

Inside the application, role-based access follows least privilege, and we review who has access every quarter.

The network denies everything by default and opens only ports 80 and 443, with production separated from non-production.

fail2ban blocks intrusion attempts in real time, Grafana provides monitoring and alerting, and security event logs are kept for at least 90 days with restricted access to change them. Access attempts are logged, successful and failed alike.

GDPR and privacy, built into the product

The privacy controls a reviewer expects are not a separate module or a support ticket. They live in Settings, on the same screens your recruiters already use.

Turn on GDPR in Settings and pick a candidate data retention period from 1 to 60 months. When that period ends, 100Hires can delete the candidate automatically and send consent renewal emails before consent expires, so you are not chasing it by hand.

Add your privacy policy URL once and it shows on every consent request a candidate sees, and on your career site footer if you want it there.

100Hires candidate profile showing per-candidate GDPR consent status and data retention end date

Honor a deletion request without a developer

Open a candidate, use the GDPR menu on the profile, and you can see consent status, request consent, or remove the profile entirely for a right-to-be-forgotten request. Deleting a profile removes all of that candidate's data. You can also run consent requests, status updates, and exports in bulk across many candidates at once from the Candidates page.

  • Per-candidate consent status
  • One request to capture or renew consent
  • Remove profile and all its data
  • Bulk consent and export actions

Privacy laws beyond GDPR

The same controls support compliance with Canadian privacy law: PIPEDA, Quebec Law 25, Alberta PIPA, and BC PIPA. Our Privacy Officer is Alex Kravets, reachable at privacy@100hires.com, and a DPA covering PIPEDA and Law 25 terms is available on request.

For candidate outreach under CASL, nurture and bulk email templates carry automatic unsubscribe links, sender identification, and suppression once a candidate opts out.

Where automated decisions are regulated, the design helps: AI Score, the AI Copilot, and the AI Email Composer default to recommendations a recruiter reviews.

An optional workflow rule can disqualify candidates below an AI Score threshold - off by default, and something you turn on per role once you trust the criteria.

Knockout questions can disqualify on a clear-cut answer, so if you hire in Quebec it is worth checking that configuration against Law 25 rules on automated decisions.

We provide template disclosure language if you want to tell candidates when AI assists your process.

Bring 100Hires to your security review

Start a free trial and put the platform in front of your IT and legal teams. We answer security questionnaires and share a data processing agreement on request.

The vendors we trust with your data

We keep the list of vendors who touch your data short, and every one of them holds SOC 2 Type II, ISO 27001, or an equivalent certification and signs a data processing agreement. We review the critical ones every year.

Sub-processors with access to your data
Sub-processor What it powers Certification
Amazon Web Services Hosting for US, Canadian, and rest-of-world accounts SOC 2 Type II, ISO 27001
Hetzner Hosting for EU accounts, in Germany ISO 27001 data centers
Postmark Transactional and candidate email SOC 2 Type II (AWS infrastructure)
Twilio SMS and text messaging SOC 2 Type II
Paddle Payment processing PCI-DSS SAQ A
Zoom Interview video and scheduling SOC 2 Type II
Gusto Candidate onboarding handoff SOC 2 Type II
OpenAI, Anthropic, Google Gemini AI Score, AI Copilot, AI Email Composer SOC 2 Type II, no training on your data

Job boards are a different case. When 100Hires distributes a posting to Indeed, LinkedIn, ZipRecruiter, Glassdoor, Google Jobs, and the other boards we support, they receive only the public job description. No candidate or customer data leaves with it.

Your data is yours to export and to delete

You can export all candidate data from the Candidates page at any time, so keeping your own copy is never blocked.

If you cancel, we hold your account data for six months in case you come back, then delete it completely: from production databases, from backups and archives, and from log files that contain personal data.

The removal is irreversible and verified, and we can issue a certificate of destruction on request.

If something goes wrong, you hear it fast

100Hires keeps documented incident response, disaster recovery, and business continuity plans, with automated backups that are tested regularly.

If a breach affecting your data is confirmed, we notify your registered contact within 72 hours with what happened and what we did, followed by a detailed report inside 7 days.

On the development side, code is scanned for vulnerabilities and dependency issues before it ships, security review is part of every change, and we do not deploy with a known vulnerability open.

Critical issues are fixed within 24 hours and high-severity issues within 7 days. Everyone with access to your data clears a background check and signs a confidentiality agreement that survives their leaving.

Security reviews for enterprise teams

Most enterprise deals now include a security questionnaire, and a vendor that will not complete one is a red flag. 100Hires completes them.

If your procurement process needs more than this page, we work with it.

For enterprise customers we answer security questionnaires, share our security policies under a mutual NDA, provide evidence of controls such as configurations and sample logs, and join a security review call with our technical team.

We are direct about where we stand: 100Hires is in the process of obtaining SOC 2 Type II attestation.

Until that is complete, our controls already map to the SOC 2 Trust Services Criteria for security, availability, and confidentiality, and we share that control documentation today so you can complete your own assessment.

To start a review or request a DPA, contact privacy@100hires.com.

Security and privacy FAQ
+ Where is our candidate data stored?
100Hires hosts your data based on your primary location. EU customers are hosted in Hetzner data centers in Germany, which hold ISO 27001 certification. Customers in the US, Canada, and the rest of the world are hosted on Amazon Web Services in the United States, which is SOC 2 Type II and ISO 27001 certified. Data is encrypted in transit with TLS 1.2+ and at rest with AES-256 in both locations.
+ Is 100Hires SOC 2 certified?
100Hires is currently in the process of obtaining SOC 2 Type II attestation. In the meantime, the controls described on this page map to the SOC 2 Trust Services Criteria for security, availability, and confidentiality, and 100Hires shares that control documentation so you can complete your own vendor assessment. The data centers 100Hires runs on are independently certified: AWS holds SOC 2 Type II and ISO 27001, and Hetzner holds ISO 27001 for its data centers. Request the documentation at privacy@100hires.com.
+ Does 100Hires use our data to train AI models?
No. 100Hires does not train its own AI models on your data, and it never sells or licenses your data. When AI features such as AI Score, the AI Copilot, or the AI Email Composer send data to an AI provider, 100Hires uses paid API tiers where the provider contractually commits not to train on your content. You can also turn every AI feature off for the whole account if your policy does not allow third-party AI.
+ Can we get a GDPR data processing agreement (DPA)?
Yes. 100Hires acts as your data processor under Article 28 of GDPR, and a GDPR-compliant DPA, including Standard Contractual Clauses for international transfers, is available on request from privacy@100hires.com. The same DPA can cover PIPEDA and Quebec Law 25 terms for Canadian customers.
+ How quickly does 100Hires notify us of a data breach?
100Hires notifies your registered contact within 72 hours of a confirmed personal data breach, in line with Article 33 of GDPR. The notice covers the nature and scope of the incident, the data affected, and the steps taken, and a detailed report follows within 7 days.
+ What happens to our data if we cancel?
You can export all candidate data from the Candidates page in 100Hires at any time. After cancellation, 100Hires keeps your account data for six months in case you reactivate, then deletes it completely from production databases, backups, and log files containing personal data. The deletion is irreversible and verified, and a certificate of destruction is available on request.
+ How does 100Hires support GDPR and right-to-erasure requests?
100Hires gives you the controls to meet your obligations as the data controller. When a candidate asks for a copy of their data, you export it from the Candidates page; when they ask to be forgotten, you remove the candidate profile, which deletes all of that candidate's data. You set retention from 1 to 60 months with optional automatic deletion, and consent is tracked per candidate with an audit trail, so you have a record of what you collected and when - you choose and document your lawful basis. Consent requests, status updates, and exports can also be run in bulk.
+ What happens to rejected candidates' data?
100Hires lets you set a candidate data retention period from 1 to 60 months, and when it expires the platform can delete those candidates automatically, so the pile of rejected applicants does not sit in your account indefinitely. You can also remove any candidate profile on demand, and consent and retention status is tracked per candidate. It is the same retention engine that backs your GDPR, PIPEDA, and Quebec Law 25 obligations.
+ Can 100Hires complete our security questionnaire or support an audit?
Yes, for enterprise customers. 100Hires answers security questionnaires, shares security policies under a mutual NDA, provides evidence of controls such as configurations and sample logs, and joins a security review call with the technical team. Start the process through your account manager or at privacy@100hires.com.
23,000+ recruiters & business owners read this newsletter

The hiring playbook, in your inbox

One email a week - benchmarks, AI screening tactics, and short interview templates from the 100Hires team. No product pitches.

Hand your security team a clear answer

Start a free 14-day trial, no credit card, and request a DPA or the full Security FAQ whenever your review needs it.

Related 100Hires resources: Explore gdpr compliant applicant tracking system and recruiting software.

We use cookies to offer you our service. By continuing to use this site, you consent to our use of cookies as described in our policy