Recruitment Smart Trust Center

Recruitment Smart is a trusted partner in AI-driven recruitment, prioritising data security and ethical AI. It employs encryption, access controls, and regular audits, and holds ISO 27001, SOC 2 Type II, GDPR, and CCPA certifications. Its responsible AI framework ensures unbiased, transparent, and human-overseen hiring decisions, with continuous bias auditing to promote fair and equitable recruitment.

Certifications
Blue circular badge with text 'AICPA SOC' and URL 'aicpa.org/soc4so' representing SOC for Service Organizations.Round blue badge with white text stating California Consumer Privacy Act and CCPA Ready with a checklist icon.ISO 27001 certified badge for Information Security Management with a globe icon in the background.Circular badge with text 'General Data Protection Regulation' around the edge, five orange stars above, 'GDPR READY' in the center, and an orange checkmark below.
Trusted By

Trusted by industry-leading companies around the globe

HCLTech company logo in dark blue letters.
NatWest logo
Malaysia Airlines logo in blue with stylized wau bulan bird graphic.
Atos company logo in dark blue text.
Blue flame shaped logo with the word PTEEP below it.
Wixz logo with stylized text and website URL wixz.alr.com below it.
Edge blue logo with stylized letters and a cutout letter D.
Altumitín company logo with stylized house icon.
Bajaj company logo with stylized blue emblem and blue text.
Injazat company logo in dark blue letters on a white background.
NRG company logo with blue text and digital pixel design at top right.
Logo with text 'John Clements' and tagline 'Your partner for life.'
ClearBridge Technology Group logo with the company name in blue text.
SCG logo with a stylized elephant head inside a circle followed by the letters S, C, and G in blue.
AB InBev company logo.
Societe Generale logo with a red and white square inside a black square, next to the text Societe Generale in black.
Alcoa company logo with a stylized diamond-shaped icon and the word 'Alcoa' in blue.
HCLTech company logo in dark blue letters.
NatWest logo
Malaysia Airlines logo in blue with stylized wau bulan bird graphic.
Atos company logo in dark blue text.
Blue flame shaped logo with the word PTEEP below it.
Wixz logo with stylized text and website URL wixz.alr.com below it.
Edge blue logo with stylized letters and a cutout letter D.
Blue puzzle piece icon above the text 'Seguridad Operativa AGF Andina group' in blue font.
Bajaj company logo with stylized blue emblem and blue text.
Injazat company logo in dark blue letters on a white background.
NRG company logo with blue text and digital pixel design at top right.
Logo with text 'John Clements' and tagline 'Your partner for life.'
ClearBridge Technology Group logo with the company name in blue text.
SCG logo with a stylized elephant head inside a circle followed by the letters S, C, and G in blue.
AB InBev company logo.
Societe Generale logo with a red and white square inside a black square, next to the text Societe Generale in black.
Alcoa company logo with a stylized diamond-shaped icon and the word 'Alcoa' in blue.
Documentation
See all documents
Certification / Standard
ISO/IEC 27001 (Information Security Management)
Request access
SOC 2 Type II
Request access
NCA ECC Report
Request access
AI Bias Report (Warden AI)
Open link
CCPA (California Consumer Privacy Act)
Request access
VAPT (Latest)
Request access
CSA STAR CAIQ
Open link
01

AI Model Architecture & Usage Controls

Control area
Description
Model Architecture

SniperAI leverages a hybrid AI architecture combining proprietary ML models with state-of-the-art LLMs to deliver high-accuracy candidate matching, ranking, and insights.

Model Flexibility

Supports multi-model orchestration with the ability to switch or integrate different LLM providers based on client requirements.

Vector Search & Matching

Uses vector embeddings to enable semantic search across large candidate datasets, improving relevance and discovery.

AI Usage Scope

AI is designed to assist in sourcing, screening, ranking, and insights generation. Final hiring decisions remain fully human-driven.

No Automated Decision-Making

SniperAI does not autonomously make hiring decisions; it provides explainable recommendations only.

Explainability

AI outputs include scoring logic, matching insights, and reasoning to ensure transparency for recruiters.

02

Data usage & privacy

Control area
Description
Customer Data Usage

Customer data is never used to train base AI models unless explicitly agreed under a separate contractual arrangement.

Data Types Processed

Includes resume data, professional information, skills, education, work experience, and recruiter inputs.

Sensitive Data Handling

Sensitive and protected attributes (e.g., health, political views, biometric data) are excluded from processing and training.

PII Protection

Personally identifiable information (PII) is pseudonymized or masked during AI processing workflows.

Data Minimization

Only required fields are processed, ensuring compliance with GDPR and data minimization principles.

Data Ownership

All candidate and customer data remains fully owned and controlled by the client.

AWS
Cloud Hosting
Microsoft
Cloud Hosting
Azure
AI Model Provider
Certification / Standard
ISO/IEC 27001 (Information Security Management)
Request access
SOC 2 Type II
Request access
NCA ECC Report
Request access
AI Bias Report (Warden AI)
Open link
CCPA (California Consumer Privacy Act)
Request access
VAPT (Latest)
Request access
CSA STAR CAIQ
Open link
Partnership
Workday
Open link
Organizational Policies
Request access
01

AI Model Architecture & Usage Controls

Control area
Description
Model Architecture

SniperAI leverages a hybrid AI architecture combining proprietary ML models with state-of-the-art LLMs to deliver high-accuracy candidate matching, ranking, and insights.

Model Flexibility

Supports multi-model orchestration with the ability to switch or integrate different LLM providers based on client requirements.

Vector Search & Matching

Uses vector embeddings to enable semantic search across large candidate datasets, improving relevance and discovery.

AI Usage Scope

AI is designed to assist in sourcing, screening, ranking, and insights generation. Final hiring decisions remain fully human-driven.

No Automated Decision-Making

SniperAI does not autonomously make hiring decisions; it provides explainable recommendations only.

Explainability

AI outputs include scoring logic, matching insights, and reasoning to ensure transparency for recruiters.

02

Data usage & privacy

Control area
Description
Customer Data Usage

Customer data is never used to train base AI models unless explicitly agreed under a separate contractual arrangement.

Data Types Processed

Includes resume data, professional information, skills, education, work experience, and recruiter inputs.

Sensitive Data Handling

Sensitive and protected attributes (e.g., health, political views, biometric data) are excluded from processing and training.

PII Protection

Personally identifiable information (PII) is pseudonymized or masked during AI processing workflows.

Data Minimization

Only required fields are processed, ensuring compliance with GDPR and data minimization principles.

Data Ownership

All candidate and customer data remains fully owned and controlled by the client.

03

Data storage, retention & security

Control area
Description
Cloud Infrastructure

Hosted on secure cloud platforms such as AWS and Microsoft Azure with regional deployment flexibility.

Encryption at Rest

All stored data is protected using AES-256 encryption.

Encryption in Transit

Data in transit is secured using TLS 1.2/1.3 protocols.

Data Retention Policy

Data is retained based on contractual or regulatory requirements and can be deleted upon client request.

Secure Deletion

Data is securely erased or anonymized after retention expiry.

Backup & Recovery

Automated encrypted backups with disaster recovery capabilities across multiple availability zones.

Data Residency

SniperAI enables region-specific data hosting through AWS and Microsoft Azure, ensuring that customer data can be stored and processed within designated jurisdictions to comply with data sovereignty laws such as GDPR, PDPA, and other regional regulations.

04

Access control & identity management

Control area
Description
Role-Based Access Control (RBAC)

Access is granted based on least privilege principles aligned with user roles.

Single Sign-On (SSO)

Supports SAML 2.0 and OAuth/OpenID Connect for enterprise identity integration.

Multi-Factor Authentication (MFA)

Enforced for privileged and administrative access.

Access Reviews

Periodic (quarterly/annual) access reviews to validate permissions.

User Lifecycle Management

Automated provisioning/deprovisioning through SCIM or identity provider integrations.

Privileged Access Segregation

Separate administrative accounts for high-privilege operations.

05

AI governance & compliance

Control area
Description
AI Governance Framework

SniperAI follows structured AI governance aligned with ISO 27001, GDPR, NYC Bias, Colorado SB, California FEHA and responsible AI practices.

Bias & Fairness Testing

Regular bias detection and fairness testing conducted during model updates.

Human Oversight

All AI recommendations are subject to recruiter validation and control.

Audit Logging

Comprehensive logging of AI actions, user activity, and system events.

Policy Reviews

AI and security policies reviewed periodically for effectiveness and compliance.

Regulatory Compliance

Designed to comply with GDPR, CCPA, and other global data protection regulations.

06

AI security & risk management

Control area
Description
Prompt Injection Protection

Input validation and monitoring mechanisms to prevent malicious prompts

Data Poisoning Prevention

Controlled data ingestion with validation and integrity checks.

Secure Development Lifecycle

Security embedded across design, development, testing, and deployment phases.

Vulnerability Management

Regular scanning, patching, and penetration testing.

Incident Response Plan

Defined procedures for detection, containment, mitigation, and reporting of security incidents.

Continuous Monitoring

Real-time monitoring of AI performance, anomalies, and security events.

07

Monitoring, logging & auditing

Control area
Description
Centralized Logging

Logs collected for system activity, AI processing, and access events.

Real-Time Monitoring

Continuous monitoring for anomalies, threats, and system health.

Audit Trails

Immutable logs for compliance, forensic analysis, and traceability.

Performance Monitoring

Metrics include latency, accuracy, and system reliability.

Internal Audits

Regular internal audits for compliance and control validation.

Third-Party Audits

External audits (e.g., SOC 2, ISO) conducted where applicable.

08

Business continuity & resilience

Control area
Description
Disaster Recovery

Multi-zone deployment with automated failover capabilities.

Backup Strategy

Encrypted backups with regular recovery testing.

High Availability

Redundant infrastructure ensuring minimal downtime.

Business Continuity Plan

Documented procedures for maintaining operations during disruptions.

09

Vendor risk & subprocessor governance

Control area
Description
Vendor Due Diligence

Security, privacy, and compliance assessments before onboarding subprocessors.

Contractual Safeguards

Data protection agreements (DPA), confidentiality clauses, and no-training clauses enforced.

Subprocessor Transparency

Customers are provided with a list of subprocessors upon request.

Periodic Reviews

Annual or periodic reassessment of vendor security posture.

Data Processing Restrictions

Subprocessors are restricted to processing data only for defined purposes.

Cross-Border Compliance

Data transfer mechanisms comply with GDPR and international data transfer regulations.

AWS
Cloud Hosting
Microsoft
Cloud Hosting
Azure
AI Model Provider

Request access to documentation

Fill out this form to request access. We'll review your request and get back to you shortly.

Thank You for submitting

Your message has been recieved
we will update you shortly.

Close
Oops! Something went wrong while submitting the form.