Recruiting Rewards handles candidate and company data with care. This page shows how we protect it, where it is stored and who processes it on our behalf. We keep it current as our setup changes.
Current status for the frameworks companies ask us about during procurement.
We process personal data under the GDPR and store it inside the EU. A data processing agreement (DPA) is available on request.
Our primary database and file storage run on AWS eu-north-1 in Stockholm, Sweden, through Supabase. Product analytics run on PostHog's EU cloud.
Preparation is underway. The certification is not in place yet, so we do not claim it.
Planned. If SOC 2 is part of your procurement, tell us and we will share where we stand.
The controls that apply to every account on the platform, not an enterprise add-on.
TLS 1.2 or higher in transit, AES-256 at rest.
Role-based access for companies, recruiters and admins, row-level security in Postgres, and admin surfaces on a separate host with a separate identity provider instance.
CVs and attachments are served through short-lived signed URLs. There are no public file links.
Sign-in is managed by Clerk, with passwordless links and OAuth supported.
Errors and performance are monitored in Sentry, with alerting to the team.
Every change goes through pull-request review, type checking, linting and CI before deploy. Our infrastructure is fully managed, with no self-hosted servers.
We run recurring internal security audits, most recently in August 2026. All critical findings were remediated before this page was published.
Payments are handled by Stripe. Card data never touches our servers, and PCI DSS compliance is covered by Stripe.
Candidates and customers can see what we hold and ask us to change or remove it.
Candidate and company data is stored in the EU, in the Stockholm region.
Requests for access, correction and deletion are handled at privacy@recruitingrewards.com.
Consent is built into the product. Candidates get their own portal where they give and review it.
We keep what a hiring process needs. Transient credentials such as sign-in links are purged automatically.
The services we rely on to run the platform, and where they hold data.
| Subprocessor | Purpose | Data location |
|---|---|---|
| Vercel | Hosting and compute | EU/US edge |
| Supabase | Database and file storage | AWS eu-north-1, Stockholm |
| Clerk | Authentication | US, with EU transfer safeguards |
| Stripe | Payments | EU/US |
| Resend | Transactional email | US |
| PostHog | Product analytics | EU cloud, Frankfurt |
| Sentry | Error monitoring | EU/US |
| Gemini AI processing and optional Google Calendar integration | EU/US | |
| Microsoft | Optional Outlook Calendar integration | EU/US |
| Pipedrive | CRM for sales contacts | EU |
The full up-to-date list and our DPA terms are available on request at privacy@recruitingrewards.com.
We welcome reports from security researchers and customers. Send what you found to security@recruitingrewards.com and we will come back to you quickly with an assessment and a plan.
We ask that you do not access, change or download data belonging to other users while testing, and that you give us reasonable time to fix an issue before publishing it. We do not run a bug bounty program.
Last updated: August 2026