Trust center

Trust and security

Recruiting Rewards handles candidate and company data with care. This page shows how we protect it, where it is stored and who processes it on our behalf. We keep it current as our setup changes.

Compliance

Where we stand today

Current status for the frameworks companies ask us about during procurement.

GDPR

Compliant

We process personal data under the GDPR and store it inside the EU. A data processing agreement (DPA) is available on request.

EU data residency

Active

Our primary database and file storage run on AWS eu-north-1 in Stockholm, Sweden, through Supabase. Product analytics run on PostHog's EU cloud.

ISO 27001

In progress

Preparation is underway. The certification is not in place yet, so we do not claim it.

SOC 2 Type II

Planned

Planned. If SOC 2 is part of your procurement, tell us and we will share where we stand.

Security

How we protect your data

The controls that apply to every account on the platform, not an enterprise add-on.

Encryption

TLS 1.2 or higher in transit, AES-256 at rest.

Access control

Role-based access for companies, recruiters and admins, row-level security in Postgres, and admin surfaces on a separate host with a separate identity provider instance.

Documents

CVs and attachments are served through short-lived signed URLs. There are no public file links.

Authentication

Sign-in is managed by Clerk, with passwordless links and OAuth supported.

Monitoring

Errors and performance are monitored in Sentry, with alerting to the team.

Secure development

Every change goes through pull-request review, type checking, linting and CI before deploy. Our infrastructure is fully managed, with no self-hosted servers.

Security audits

We run recurring internal security audits, most recently in August 2026. All critical findings were remediated before this page was published.

Payments

Payments are handled by Stripe. Card data never touches our servers, and PCI DSS compliance is covered by Stripe.

Privacy

Your data, and the rights that come with it

Candidates and customers can see what we hold and ask us to change or remove it.

Data residency

Candidate and company data is stored in the EU, in the Stockholm region.

Data subject rights

Requests for access, correction and deletion are handled at privacy@recruitingrewards.com.

Candidate consent

Consent is built into the product. Candidates get their own portal where they give and review it.

Data minimization

We keep what a hiring process needs. Transient credentials such as sign-in links are purged automatically.

Subprocessors

Who processes data on our behalf

The services we rely on to run the platform, and where they hold data.

SubprocessorPurposeData location
VercelHosting and computeEU/US edge
SupabaseDatabase and file storageAWS eu-north-1, Stockholm
ClerkAuthenticationUS, with EU transfer safeguards
StripePaymentsEU/US
ResendTransactional emailUS
PostHogProduct analyticsEU cloud, Frankfurt
SentryError monitoringEU/US
GoogleGemini AI processing and optional Google Calendar integrationEU/US
MicrosoftOptional Outlook Calendar integrationEU/US
PipedriveCRM for sales contactsEU

The full up-to-date list and our DPA terms are available on request at privacy@recruitingrewards.com.

Responsible disclosure

Found something? Tell us.

We welcome reports from security researchers and customers. Send what you found to security@recruitingrewards.com and we will come back to you quickly with an assessment and a plan.

We ask that you do not access, change or download data belonging to other users while testing, and that you give us reasonable time to fix an issue before publishing it. We do not run a bug bounty program.

security@recruitingrewards.com

Last updated: August 2026