Compliance &
Security

Protect your data, ensure compliance, and build a future-ready hiring process with confidence.

PyHire security dashboard: a Security Overview panel confirming Data Encryption, Access Control, Threat Detection and Backup Status; a Compliance Status ring at 100% compliant, broken down as 72% compliant, 20% in progress and 8% not compliant; an Audit Readiness card showing 92% of systems compliant; and a Risk Overview gauge reading Low Risk 12
Compliance & Security

Recruitment data is personal data, and hiring is a regulated activity

A recruitment system holds an unusual concentration of sensitive information: identity documents, contact details, employment history, salary expectations, interview assessments and rejection reasons — for people who are not your employees and who never signed anything beyond a consent to be considered.

PyHire treats that as the design constraint rather than as a feature to be added later. Data is encrypted at rest with AES-256 and in transit over TLS 1.2 or above. Access is governed by role-based permissions checked before any record is returned. Every action, view and export is written to an audit log. Retention policies run automatically against the records that have passed their retention period.

Two obligations sit in tension in every recruitment system, and both have to be met. Candidates have a right to have their data erased. Regulators and clients expect a complete, unaltered record of how hiring decisions were made. PyHire's approach is anonymisation in place — personal identifiers are removed while the process record they belonged to remains intact — so a right-to-be-forgotten request does not create a hole in an audit trail.

For teams hiring in India, this is what DPDP readiness means in practice: consent captured at the point of collection, purpose limitation enforced by access control, retention handled by policy rather than by remembering, and erasure honoured without destroying the evidence of a defensible process.

Powerful Features

Everything you need to succeed with Compliance & Security

Enterprise Encryption

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Role-Based Access

Granular permissions ensure users only see the data they need.

GDPR & CCPA Ready

Built-in tools for data anonymization, consent management, and right-to-be-forgotten requests.

Comprehensive Audit Logs

Track every action, view, and export across your entire workspace.

Enterprise Encryption

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Role-Based Access

Granular permissions ensure users only see the data they need.

GDPR & CCPA Ready

Built-in tools for data anonymization, consent management, and right-to-be-forgotten requests.

Comprehensive Audit Logs

Track every action, view, and export across your entire workspace.

Enterprise Encryption

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Role-Based Access

Granular permissions ensure users only see the data they need.

GDPR & CCPA Ready

Built-in tools for data anonymization, consent management, and right-to-be-forgotten requests.

Comprehensive Audit Logs

Track every action, view, and export across your entire workspace.

What enterprise-grade actually means here

Four controls that determine whether a recruitment platform can be trusted with candidate data.

Access control that is enforced, not advisory

Users authenticate through SSO using SAML or OAuth with MFA enforcement, and every request is checked against the user's role before any record is returned.

The distinction that matters is where the check happens. Hiding a record from a user interface is not access control — the data was still retrieved. PyHire verifies permission before granting access to the record, which is what makes it safe to give clients and external vendors direct access to the parts of the system that concern them.

In multi-client and multi-vendor operations this is the control that carries the most weight: granular permissions ensure each party sees only what they need to, and that boundary is enforced by the platform rather than by policy.

Encryption and the shape of the data

Candidate data is encrypted at rest using AES-256, and all traffic is carried over TLS 1.2 or above. Documents — resumes, identity papers, offer letters — are handled under the same protection as structured records.

Continuous compliance scanning monitors for PII exposure and policy adherence, which addresses the practical failure mode in recruitment: sensitive information arriving in an unexpected place, such as a document attached where it did not belong.

Audit logs that hold up under review

Every read, write and export is logged immutably. The log covers viewing, not only editing — which matters, because unauthorised access to candidate data usually looks like reading it rather than changing it.

An immutable log is also what makes a hiring process defensible. When a decision is challenged, the question is what was actually done and by whom, and a record that could have been amended afterwards does not answer it.

Communication history is held to the same standard: a complete, uneditable trail of every interaction with a candidate.

Retention and erasure without contradiction

Retention policies are configured once and enforced automatically, so records that have passed their retention period are deleted on schedule rather than accumulating until someone notices.

Right-to-be-forgotten requests are handled through anonymisation in place. Personal identifiers are removed from the candidate record while the process history that references it stays intact — so the individual is no longer identifiable and the audit chain is not broken.

Consent management records what a candidate agreed to and when, which is the evidence a regulator asks for first when questioning why data was held at all.

Secure by Design

How we protect your sensitive candidate and corporate data.

01Access Control
Users authenticate via SSO (SAML/OAuth) with MFA enforcement.
02Permission Check
System verifies user roles before granting access to records.
03Data Encryption
Information is retrieved via secure, encrypted channels.
04Action Auditing
Every read, write, and export is logged immutably.
05Compliance Scans
Continuous monitoring for PII exposure and policy adherence.
06Data Retention
Automated deletion of old records per compliance policies.

Who this matters to

Compliance requirements arrive from different directions depending on where and how you hire.

In-house HR teams in India

DPDP obligations around consent, purpose limitation and erasure apply, but the hiring process runs on tools that were not built with them in mind.

With PyHireConsent, retention and erasure are handled by the platform's own workflows rather than by manual discipline.

Organisations hiring internationally

GDPR and CCPA add anonymisation, consent and right-to-be-forgotten requirements on top of local law.

With PyHireBuilt-in privacy tooling means international obligations are met without a separate manual process per jurisdiction.

Agencies handling client candidate data

Client data protection obligations flow through to you as a processor, and clients audit for it.

With PyHireRole-based access, encryption and complete audit logs make data handling demonstrable rather than asserted.

Enterprise security and IT teams

A new system needs to meet identity, access and logging standards before it can be approved.

With PyHireSSO with SAML/OAuth, MFA enforcement, encryption in transit and at rest, and immutable workspace-wide audit logs.

Peace of Mind for Enterprise

Focus on hiring while we handle the complex regulatory and security landscape.

Peace of Mind for Enterprise — PyHire Compliance & Security

Mitigate Risk

Prevent data breaches and compliance violations with proactive security measures.

Global Compliance

Easily adhere to international privacy laws without manual effort.

Secure Collaboration

Share candidate data internally and externally with absolute confidence.

Automated Governance

Set retention policies and let the system manage data lifecycles.

Mitigate Risk

Prevent data breaches and compliance violations with proactive security measures.

Global Compliance

Easily adhere to international privacy laws without manual effort.

Secure Collaboration

Share candidate data internally and externally with absolute confidence.

Automated Governance

Set retention policies and let the system manage data lifecycles.

Frequently Asked Questions

Learn about our security practices.

Yes, we undergo regular SOC 2 Type II audits to verify our security controls.
Yes, we support SAML 2.0 integrations with Okta, Azure AD, Google Workspace, and more. SSO is available on the enterprise plan, and MFA can be enforced at the point of authentication.
Data is hosted in secure AWS/GCP regions, with options for EU-only or US-only data residency.
Data is encrypted at rest using AES-256 and in transit over TLS 1.2 or above. Documents such as resumes, identity papers and offer letters are protected on the same basis as structured candidate records.
Through anonymisation in place. Personal identifiers are removed from the candidate record while the process history referencing it remains intact, so the individual is no longer identifiable and the audit chain is not broken. This is what allows erasure obligations and record-keeping obligations to be met at the same time.
Every action, view and export across the workspace, written immutably. The log covers reads and not only changes, because unauthorised access to candidate data usually takes the form of viewing it rather than editing it.
PyHire's controls are aligned for DPDPA: consent is captured at the point of collection, purpose limitation is enforced through role-based access, retention runs on policy rather than on memory, and erasure is honoured without destroying the process record.
Yes. Retention policies are configured once and enforced automatically, so records that pass their retention period are removed on schedule rather than accumulating until someone reviews them.
A recruitment team using PyHire Compliance & Security

Ready to Secure Your Recruitment?

Ensure compliance, protect candidate privacy, and secure your hiring data with PyHire.

Book a Demo Today