Trust and security
Recruiting Rewards handles candidate and company data with care. This page shows how we protect it, where it is stored and who processes it on our behalf. We keep it current as our setup changes.
Where we stand today
Current status for the frameworks companies ask us about during procurement.
GDPR
We process personal data under the GDPR and store it inside the EU. A data processing agreement (DPA) is available on request.
EU data residency
Our application runs on Vercel with compute in Stockholm (AWS eu-north-1), and our primary database and file storage run in the same region through Supabase. Product analytics run on PostHog's EU cloud.
ISO 27001
Preparation is underway. The certification is not in place yet, so we do not claim it.
SOC 2 Type II
Planned. If SOC 2 is part of your procurement, tell us and we will share where we stand.
How we protect your data
The controls that apply to every account on the platform, not an enterprise add-on.
Encryption
TLS 1.2 or higher in transit, AES-256 at rest.
Access control
Role-based access for companies, recruiters and admins, row-level security in Postgres, and admin surfaces on a separate host with a separate identity provider instance.
Documents
CVs and attachments are served through short-lived signed URLs. There are no public file links.
Authentication
Sign-in is managed by Clerk, with passwordless links and OAuth supported.
Monitoring
Errors and performance are monitored in Sentry, with alerting to the team.
Secure development
Every change goes through pull-request review, type checking, linting and CI before deploy. Our infrastructure is fully managed, with no self-hosted servers.
Security audits
We run recurring internal security audits, most recently in August 2026. All critical findings were remediated before this page was published.
Payments
Payments are handled by Stripe. Card data never touches our servers, and PCI DSS compliance is covered by Stripe.
Your data, and the rights that come with it
Candidates and customers can see what we hold and ask us to change or remove it.
Data residency
Candidate and company data is stored in the EU, in the Stockholm region.
Data subject rights
Requests for access, correction and deletion are handled at privacy@recruitingrewards.com.
Candidate consent
Consent is built into the product. Candidates get their own portal where they give and review it.
Data minimization
We keep what a hiring process needs. Transient credentials such as sign-in links are purged automatically.
Who processes data on our behalf
The services we rely on to run the platform, and where they hold data.
| Subprocessor | Purpose | Data location |
|---|---|---|
| Vercel | Hosting and compute | Compute in AWS eu-north-1, Stockholm; global CDN |
| Supabase | Database and file storage | AWS eu-north-1, Stockholm |
| Clerk | Authentication | US, with EU transfer safeguards |
| Stripe | Payments | EU/US |
| Resend | Transactional email | US |
| PostHog | Product analytics | EU cloud, Frankfurt |
| Sentry | Error monitoring | EU/US |
| Gemini AI processing and optional Google Calendar integration | EU/US | |
| Microsoft | Optional Outlook Calendar integration | EU/US |
| Pipedrive | CRM for sales contacts | EU |
The full up-to-date list and our DPA terms are available on request at privacy@recruitingrewards.com.
Found something? Tell us.
We welcome reports from security researchers and customers. Send what you found to security@recruitingrewards.com and we will come back to you quickly with an assessment and a plan.
We ask that you do not access, change or download data belonging to other users while testing, and that you give us reasonable time to fix an issue before publishing it. We do not run a bug bounty program.
Last updated: August 2026