Security & data protection

Your candidates’ data, handled properly.

OctoRecruit is built for recruitment teams everywhere. We treat candidate data as what it is — sensitive personal information — with mailbox access you control and can revoke, encryption, strict per-account isolation, and AI that never trains on your data.

  • EU primary storage
  • Encrypted mailbox tokens
  • Per-account RLS isolation
  • No AI training
  • Revoke access anytime
How we protect your data

Built on real safeguards, not promises

Every item below is a capability already baked into how OctoRecruit works.

  • Mailbox access you control

    OctoRecruit connects to Gmail and Outlook to pull in candidate CVs and threads, and sends email only when you compose it, schedule it, or switch on a pipeline automation. You can revoke access at any time from your provider or our settings.

  • Encrypted OAuth tokens

    The tokens that let us read your mailbox are encrypted at rest using AES-GCM before they are stored. They are decrypted only in memory when a sync runs on your behalf.

  • Per-account data isolation

    Every record is protected by Supabase Row-Level Security, scoped to your account. One customer can never read another customer’s candidates, jobs or messages — the database enforces it, not just the app.

  • Data residency

    Primary storage is in the EU: Supabase on AWS eu-central-1. A named set of sub-processors — including the AI providers we use to parse and score CVs — process data in the US under Standard Contractual Clauses. See our GDPR commitment below for the full list.

  • Admin audit logging

    Sensitive administrative actions are recorded in an audit log, so there is an accountable trail of who did what and when across privileged operations.

  • Hardened by default

    The app ships with a Content Security Policy and a baseline set of security headers, reducing the surface for cross-site scripting and other common web attacks.

  • Your data never trains AI

    Candidate data is used only to score and parse CVs for you. It is never used to train AI models — yours or anyone else’s.

  • Deletion and retention

    Delete a candidate and the record is soft-deleted, then permanently erased — including removing its CV file from storage — starting 30 days later; a large backlog is worked through oldest-first, so a heavy backlog can delay full erasure past that window. You can also set a retention window in Settings so untouched candidates are erased automatically, with purges logged for audit.

How AI uses your data

Transparent by design

To score and parse a CV, we send its text to our AI provider so it can rate the candidate 1–10 with a reason, extract structured fields, and run the deeper analyses you request — for you. That is the only purpose.

  • We send CV text to the AI provider only to score, parse, and analyse it for you — to produce the ranking, the structured profile, and the analyses you see in your dashboard.
  • Your candidate data is never used to train AI models. Scoring is a read-and-rate operation, not a training one.
  • Every score comes with a plain-language reason, so there is no black box — you can always see why a candidate ranks where they do.
Data protection

What it means in practice — and where to read it in full.

  • Primary storage in the EU: Supabase on AWS eu-central-1.
  • Our sub-processor list is published in full, with at least 14 days’ notice before we add a new one that materially changes our processing activities.
  • A Data Processing Agreement on request, and data-subject requests answered within 30 days, extendable to 3 months for complex requests with notice.

Found a security issue? Report it to ··· with steps to reproduce. Please give us a chance to fix it before disclosing it publicly.

Recruiting that respects candidate data.

Join our early-access programme and see how OctoRecruit handles your pipeline.