Security
No badges, no percentages, no reassuring vagueness. What follows is a plain description of how the system is built, what it protects, and — at the bottom — what we haven't done yet.
Being specific about this is the point. If you're evaluating us, you should be able to see the whole surface at once.
| Category | What that means in practice |
|---|---|
| Candidate data | CVs and the text extracted from them, contact details, application history, interview notes, scorecards, assessment results, reference responses |
| Employment records | Signed contracts, identity and right-to-work documents, salary and bonus figures, payslips, bank and payment details, tax dependants, leave and sick-leave records |
| Commercial data | Client companies and contacts, proposals and rates, placement terms, invoices, margin and cost figures, recruiter commissions |
| Operational data | Equipment assignments, third-party system access records, timesheets, goals and review notes |
| Communications | Messages sent to candidates and employees across every channel, and replies received back into the system |
Some of this is among the most sensitive data a company holds about a person. We treat the whole set at that level rather than tiering it.
This is what makes a system this broad usable rather than alarming. Access is controlled at three levels, not one.
Your employees see only themselves. The self-service portal is a separate surface with its own boundary — an employee filing a timesheet has no path to anyone else's records.
Your clients see only their own people, through a portal scoped to their company, with every view and action recorded.
Employees who only use the self-service portal aren't required to set up two-factor, because they have no access to anyone's records but their own. Every user who can see other people's data is.
Administrators can read both logs in the app, and they're covered by the same export rights as everything else.
Every vendor has a version of this list. Most don't publish it.
If any of those is disqualifying for you, we'd rather you knew now than after a migration. And if you need something specific for your own review, ask — we'll answer precisely, including when the answer is no.
Email security@easycruiter.com and you'll get a human reply within one business day. We won't threaten you, we'll tell you what we did about it, and we'll credit you if you'd like.
If you're testing, please use your own trial workspace and don't touch anyone else's data. That's the only rule.