Your candidates’ data, handled properly.
OctoRecruit is built for recruitment teams everywhere. We treat candidate data as what it is — sensitive personal information — with mailbox access you control and can revoke, encryption, strict per-account isolation, and AI that never trains on your data.
- EU primary storage
- Encrypted mailbox tokens
- Per-account RLS isolation
- No AI training
- Revoke access anytime
Built on real safeguards, not promises
Every item below is a capability already baked into how OctoRecruit works.
Mailbox access you control
OctoRecruit connects to Gmail and Outlook to pull in candidate CVs and threads, and sends email only when you compose it, schedule it, or switch on a pipeline automation. You can revoke access at any time from your provider or our settings.
Encrypted OAuth tokens
The tokens that let us read your mailbox are encrypted at rest using AES-GCM before they are stored. They are decrypted only in memory when a sync runs on your behalf.
Per-account data isolation
Every record is protected by Supabase Row-Level Security, scoped to your account. One customer can never read another customer’s candidates, jobs or messages — the database enforces it, not just the app.
Data residency
Primary storage is in the EU: Supabase on AWS eu-central-1. A named set of sub-processors — including the AI providers we use to parse and score CVs — process data in the US under Standard Contractual Clauses. See our GDPR commitment below for the full list.
Admin audit logging
Sensitive administrative actions are recorded in an audit log, so there is an accountable trail of who did what and when across privileged operations.
Hardened by default
The app ships with a Content Security Policy and a baseline set of security headers, reducing the surface for cross-site scripting and other common web attacks.
Your data never trains AI
Candidate data is used only to score and parse CVs for you. It is never used to train AI models — yours or anyone else’s.
Deletion and retention
Delete a candidate and the record is soft-deleted, then permanently erased — including removing its CV file from storage — starting 30 days later; a large backlog is worked through oldest-first, so a heavy backlog can delay full erasure past that window. You can also set a retention window in Settings so untouched candidates are erased automatically, with purges logged for audit.
Transparent by design
To score and parse a CV, we send its text to our AI provider so it can rate the candidate 1–10 with a reason, extract structured fields, and run the deeper analyses you request — for you. That is the only purpose.
- We send CV text to the AI provider only to score, parse, and analyse it for you — to produce the ranking, the structured profile, and the analyses you see in your dashboard.
- Your candidate data is never used to train AI models. Scoring is a read-and-rate operation, not a training one.
- Every score comes with a plain-language reason, so there is no black box — you can always see why a candidate ranks where they do.
Our GDPR commitment
What it means in practice — and where to read it in full.
- Primary storage in the EU: Supabase on AWS
eu-central-1. - Our sub-processor list is published in full, with at least 14 days’ notice before we add a new one that materially changes our processing activities.
- A Data Processing Agreement on request, and data-subject requests answered within 30 days, extendable to 3 months for complex requests with notice.
Found a security issue? Report it to ··· with steps to reproduce. Please give us a chance to fix it before disclosing it publicly.
Recruiting that respects candidate data.
Join our early-access programme and see how OctoRecruit handles your pipeline.
