SECURITY & COMPLIANCE

Security for candidate data

Control access to candidate information, set retention periods, and review account activity. Our Trust Center contains the SOC 2 Type II report and supporting security documentation.

View complete Trust Center →

Security reports, controls and supporting documentation

Read how we test the AI →
SOC 2 Type II
Third-party security audit
GDPR
EU data protection law
CCPA
California privacy law

Where your data lives

Screened's core application data is stored in AWS data centers in the United States. For international customers, data transfers are protected by Standard Contractual Clauses (SCCs) as detailed in our Data Processing Agreement.

View our DPA

Infrastructure security

SOC 2-audited infrastructure with network isolation, DDoS protection, and annual penetration tests.

Cloud & data

Hosted in SOC 2-audited data centers with encryption at rest and in transit. Automated backups with point-in-time recovery and real-time monitoring.

Network & testing

Isolated networks with firewall rules and DDoS protection. Intrusion detection enabled and annual penetration testing conducted by independent third parties.

Role-based access controls

Control exactly who on your team sees candidate data. Each role only accesses what it needs, from full admin control down to limited hiring team access. Support access is restricted and logged.

An audit trail for screening decisions

Review candidate activity and recorded decisions, including who made a change and when. Use the account audit log for team, integration, and export activity.

Set candidate data retention periods

Choose how long to keep candidate records, with a separate retention setting for interview recordings.

Compliance details

SOC 2 TYPE II

Annual security audit

Review our SOC 2 Type II report in the Trust Center for the audited controls, scope, and reporting period.

Audited annually
GDPR

EU data protection

Screened supports your GDPR obligations with a DPA, SCCs, and straightforward support for erasure and data portability requests.

View our DPA
CCPA

California privacy

Screened supports your CCPA obligations with clear service provider terms and built-in workflows for data access and deletion requests.

View privacy policy

Ready to get started?

Talk to us about your security and compliance requirements.

Common questions

Access depends on your team’s assigned roles and permissions. Screened support access is restricted and logged. See our DPA for details of the service providers involved in processing candidate data.

Screened's core application data is stored in AWS data centers in the United States. Approved sub-processors may process candidate data elsewhere. For international customers, transfers are protected by Standard Contractual Clauses (SCCs). See our DPA for details.

Candidate data retention is configurable from 1 month to 5 years based on your compliance needs. Recording availability is set separately, from 1 to 12 months.

We test whether selected names or personal details affect AI screening recommendations, using fictional profiles and repeated scoring. See the published reports and their limitations. These are internal tests, not an independent audit.

Visit our Trust Center for SOC 2 reports, security documentation, and compliance details. For specific questions, reach out through our contact page.