Security

We're asking to hold employment contracts and payslips. Here's exactly how we handle that.

No badges, no percentages, no reassuring vagueness. What follows is a plain description of how the system is built, what it protects, and — at the bottom — what we haven't done yet.

What's actually in here

Being specific about this is the point. If you're evaluating us, you should be able to see the whole surface at once.

CategoryWhat that means in practice
Candidate dataCVs and the text extracted from them, contact details, application history, interview notes, scorecards, assessment results, reference responses
Employment recordsSigned contracts, identity and right-to-work documents, salary and bonus figures, payslips, bank and payment details, tax dependants, leave and sick-leave records
Commercial dataClient companies and contacts, proposals and rates, placement terms, invoices, margin and cost figures, recruiter commissions
Operational dataEquipment assignments, third-party system access records, timesheets, goals and review notes
CommunicationsMessages sent to candidates and employees across every channel, and replies received back into the system

Some of this is among the most sensitive data a company holds about a person. We treat the whole set at that level rather than tiering it.

Your workspace is separate, at the query level

Recruiters, HR, finance, your employees and your clients can share one system safely

This is what makes a system this broad usable rather than alarming. Access is controlled at three levels, not one.

Your employees see only themselves. The self-service portal is a separate surface with its own boundary — an employee filing a timesheet has no path to anyone else's records.

Your clients see only their own people, through a portal scoped to their company, with every view and action recorded.

Authentication

Employees who only use the self-service portal aren't required to set up two-factor, because they have no access to anyone's records but their own. Every user who can see other people's data is.

Everything is written down

Administrators can read both logs in the app, and they're covered by the same export rights as everything else.

It's yours, and leaving is easy on purpose

What we haven't done yet

Every vendor has a version of this list. Most don't publish it.

  • We don't hold a security certification. No completed audit, and we won't imply one with a badge that means something else.
  • We don't publish an uptime commitment. We're young enough that a number would be a guess, and a guessed number is worse than none.
  • We haven't had an independent penetration test. When we do, we'll say who did it and what they found.
  • We're a small team. There's no 24-hour security operations centre. There is a real person who answers, quickly, and who will tell you the truth about an incident.

If any of those is disqualifying for you, we'd rather you knew now than after a migration. And if you need something specific for your own review, ask — we'll answer precisely, including when the answer is no.

Found something?

Email security@easycruiter.com and you'll get a human reply within one business day. We won't threaten you, we'll tell you what we did about it, and we'll credit you if you'd like.

If you're testing, please use your own trial workspace and don't touch anyone else's data. That's the only rule.