Security and data
Where your candidates' data lives, and who can touch it.
Written for the person who has to say yes to a new tool holding other people's careers. Each line is something the product does today.
Mumbai
where the database lives
No passwords
sign-in by a one-time code to your work email
Consent first
no check runs without the candidate's recorded yes
Yours alone
every request checked against the company it belongs to
Your team sees your hiring. Nobody else's, and no more than they need.
Checked on our servers, not only in the screens
Before any row is read, the server works out which company you belong to and reads only that company's data. Hiding something in a page is never the only thing keeping it private.
Interviewers see what they interview
Someone added to a panel sees the applications they are assigned to, not the whole pipeline.
No contact details until your domain is proved
Applicants' email and phone stay hidden until you confirm you control your company's email domain, checked exactly rather than by a look-alike.
Shared shortlists expire in 30 days
A link you paste into a chat stops working on its own. If its date cannot be read, it is treated as expired rather than left open.
Nothing is run against a candidate without them.
Their trust is what makes the evidence worth anything, so the product is built to keep it.
A recorded yes before any check
A check is requested against a named applicant, who says yes or no on a page of their own. Silence for 14 days ends it, and nothing is run.
No Aadhaar number, anywhere
No table holds one, and a test fails the build if one is ever added. An EPFO passbook is read once for its employers and months, and never stored.
They answer before you judge
Where a record disagrees with itself, the candidate is asked first, and their answer sits beside the two facts. A flag is a question, never a verdict.
Software never rejects anyone
The product proposes; a person decides. Nobody is advanced, passed over or written to without someone on your team pressing a button.
Every hiring decision can show its working.
An audit pack for every role
Every requirement, each applicant against it, every scorecard with its evidence, every status change and who made it. On every plan.
A record of every step
Each request, answer and check is logged with its time and the person who took it, and can be downloaded whenever you need it.
Your data leaves with you
Export applicants, roles, pipeline and audit packs at any time, on every plan including the free one. Nothing is held back to keep you.
The usual doors, closed.
Encrypted, and it insists
Every connection is encrypted, and browsers are told never to try a plain one for this domain.
Cannot be framed
No other site can embed these pages, which closes the trick of disguising an approve or delete button inside someone else's page.
No password to steal
Each sign-in is a one-time code sent to a work email. There is nothing to reuse from another site's leak and nothing to phish.
Every service that receives personal data, and where it does.
Each is bound by a data processing agreement. A test holds this list against every call our servers make, so it cannot quietly fall out of date.
Supabase
Database, sign-in and file storage. Everything stored in the product.
Mumbai, India (ap-south-1)
Cloudflare
Hosting, network edge and bot protection on forms. Requests passing through, including IP addresses.
Global edge network
Google (Gemini)
Language models that draft, search and summarise for SCOUT and VERA. The profile, role and message text a task needs, and an EPFO passbook a candidate chooses to upload for VERA (read for employer names and months; the file isn't kept).
United States and other Google regions
OpenRouter
A second route to language models when the first is unavailable. The same task text as above, when used.
United States
Resend
Sending email. Recipient address, name and the message itself.
United States
AssemblyAI
Transcribing call recordings you choose to upload. The recording and the transcript.
United States
Firecrawl
Reading public web pages: a company's own website, and the links an applicant chose to give when your team asks what they show. The page address, which for an applicant's link can be their personal site or portfolio, and the public page it returns.
United States
SCOUT also reads public sources, a licensed people index and job boards with searches built from your role. Those receive no data about your applicants.
The certificates we do not hold, said before you have to ask.
No SOC 2 or ISO 27001 yet
We do not hold either certificate today, so you will not find the badges here. Send your security questionnaire and we answer it in writing.
No licensed check provider yet
Background checks run only on your own test applicants, and every result says it is simulated, until a licensed provider is connected.
A data processing agreement you can read first
We act as your processor for applicant data. Our agreement is published in full; ask and we countersign it, or review yours.
Questions a security review asks
In our database in Mumbai. Some of the service providers listed on this page process data outside India, mostly in the United States; each one says where.
Put one real role through it
Free for one open role, with every protection on this page switched on from the start.