Encryption
AES-256 encryption at rest and TLS 1.3 in transit on all connections. Secure key management with rotation policies.
This page didn't load correctly. Please check your connection and try again.
Enterprise-grade security, GDPR compliance, and EU AI Act readiness — built into the platform architecture, not bolted on.
SOC 2 documentation and security questionnaires available under NDA.
Jobful is audited, documented, and built to the regulatory frameworks that matter for enterprise hiring in the EU.
Third-party audited security controls covering availability, confidentiality, and data processing integrity — with annual clean audit reports. Full SOC 2 documentation is available on request under NDA.
Data Processing Agreement (DPA) available, lawful bases documented per Art. 6, right-to-erasure automation, data portability, and privacy by default. Governed by Romanian law and the EU General Data Protection Regulation.
Recruitment AI is classified high-risk under EU AI Act Annex III — Jobful is built to that standard: human oversight on every decision, explainable scoring, consent gates, and unalterable audit trails that satisfy Art. 12 logging requirements.
All customer data and AI inference run exclusively in EU regions. No customer data leaves EU infrastructure without explicit opt-in. Backed by Supabase EU infrastructure and Cloudflare's European edge network.
Multiple independent layers of protection — so that no single failure creates a breach.
AES-256 encryption at rest and TLS 1.3 in transit on all connections. Secure key management with rotation policies.
Role-based permissions (RBAC) with field-level restrictions, geographic access controls, and a complete audit trail on every user action.
SAML 2.0 and OAuth 2.0 support. Enterprise SSO connects to your existing identity provider — no new credentials to manage.
Every action timestamped and logged — including every AI-assisted action. Audit trails are unalterable and satisfy EU AI Act Art. 12 logging requirements.
Annual third-party security audits and penetration testing with a structured vulnerability management program covering remediation and disclosure.
99.9%+ uptime SLA backed by Cloudflare's edge network. Regular data backups and tested disaster recovery procedures.
The EU AI Act classifies recruitment and HR AI as high-risk under Annex III. Here's how Jobful meets that standard in practice.
how_to_regNo automated rejections
Every AI recommendation requires explicit human approval before any candidate is moved, shortlisted, or rejected. Candidates are never rejected by AI alone — the system is architecturally incapable of acting without a recruiter confirming the decision.
infoExplainable scoring
Every fit score comes with a structured explanation: what requirements are met, what's missing, and why. Recruiters see the reasoning before they see the recommendation — enabling meaningful human oversight rather than rubber-stamping.
policyData minimization
No protected characteristics (age, gender, origin, disability) are used in scoring — in line with GDPR Art. 5 data minimization and EU AI Act non-discrimination requirements. Your candidate data never trains models serving other customers.
visibilityCandidate transparency
Candidates are clearly informed when they interact with AI-assisted features. Any candidate can request human review at any stage of the process — a right Jobful surfaces explicitly rather than burying in a privacy policy.
Jobful is a data processor under GDPR — your organization remains the data controller. We give you the tools and documentation to meet your obligations.
Email privacy@jobful.io with your request. We respond within 30 days in line with GDPR Art. 12 timelines.
Data exports are provided in JSON or CSV format. Erasure requests include a written confirmation with an audit timestamp.
Candidates interacting with a Jobful-powered hiring process can request human review of any AI-assisted stage by contacting the recruiting organization's privacy contact, which is disclosed in every hiring workflow.
Lawful bases (Art. 6 GDPR)
All processing activities are documented with their lawful basis — consent, legitimate interest, or contract performance — available in the DPA and on request.
Security questionnaires, SOC 2 reports, and DPA documentation are available on request. We take all security reports seriously.
Security questionnaires, penetration test summaries, and compliance documentation available under NDA.
mailsecurity@jobful.ioGDPR data subject requests, DPA execution, and privacy documentation. Responses within 30 days.
mailprivacy@jobful.ioFound a vulnerability? We take all reports seriously and respond promptly. Please do not disclose publicly before we've had a chance to investigate.
mailsecurity@jobful.ioWe support security reviews, DPA execution, and SOC 2 documentation requests. Book a demo or contact our security team directly.