Trust & Compliance

Security & Trust

Enterprise-grade security, GDPR compliance, and EU AI Act readiness — built into the platform architecture, not bolted on.

verified_userSOC 2 Type IIlockGDPR Compliantauto_awesomeEU AI Act Ready

SOC 2 documentation and security questionnaires available under NDA.

Security overviewLive
SOC 2 Type II auditAnnual · third-party audited
Clean report
EU data residencyAll data & AI inference in EU
Enforced
Penetration testingAnnual third-party security audit
Up to date
Uptime SLAWith backup & disaster recovery
99.9%+
verified_userAll AI actions logged per EU AI Act requirements
Certifications & compliance

Verified, not just claimed

Jobful is audited, documented, and built to the regulatory frameworks that matter for enterprise hiring in the EU.

verified_user

SOC 2 Type II

Third-party audited security controls covering availability, confidentiality, and data processing integrity — with annual clean audit reports. Full SOC 2 documentation is available on request under NDA.

lock

GDPR by design

Data Processing Agreement (DPA) available, lawful bases documented per Art. 6, right-to-erasure automation, data portability, and privacy by default. Governed by Romanian law and the EU General Data Protection Regulation.

smart_toy

EU AI Act compliant

Recruitment AI is classified high-risk under EU AI Act Annex III — Jobful is built to that standard: human oversight on every decision, explainable scoring, consent gates, and unalterable audit trails that satisfy Art. 12 logging requirements.

public

EU data residency

All customer data and AI inference run exclusively in EU regions. No customer data leaves EU infrastructure without explicit opt-in. Backed by Supabase EU infrastructure and Cloudflare's European edge network.

Security architecture

Defence in depth

Multiple independent layers of protection — so that no single failure creates a breach.

lock

Encryption

AES-256 encryption at rest and TLS 1.3 in transit on all connections. Secure key management with rotation policies.

manage_accounts

Access control

Role-based permissions (RBAC) with field-level restrictions, geographic access controls, and a complete audit trail on every user action.

key

SSO & identity

SAML 2.0 and OAuth 2.0 support. Enterprise SSO connects to your existing identity provider — no new credentials to manage.

receipt_long

Audit logging

Every action timestamped and logged — including every AI-assisted action. Audit trails are unalterable and satisfy EU AI Act Art. 12 logging requirements.

security_update_good

Penetration testing

Annual third-party security audits and penetration testing with a structured vulnerability management program covering remediation and disclosure.

cloud_done

Uptime & recovery

99.9%+ uptime SLA backed by Cloudflare's edge network. Regular data backups and tested disaster recovery procedures.

Responsible AI

Recruitment AI is high-risk. We take that seriously.

The EU AI Act classifies recruitment and HR AI as high-risk under Annex III. Here's how Jobful meets that standard in practice.

how_to_regNo automated rejections

Humans decide. Always.

Every AI recommendation requires explicit human approval before any candidate is moved, shortlisted, or rejected. Candidates are never rejected by AI alone — the system is architecturally incapable of acting without a recruiter confirming the decision.

infoExplainable scoring

No black-box outputs.

Every fit score comes with a structured explanation: what requirements are met, what's missing, and why. Recruiters see the reasoning before they see the recommendation — enabling meaningful human oversight rather than rubber-stamping.

policyData minimization

Protected characteristics stay out.

No protected characteristics (age, gender, origin, disability) are used in scoring — in line with GDPR Art. 5 data minimization and EU AI Act non-discrimination requirements. Your candidate data never trains models serving other customers.

visibilityCandidate transparency

Clear disclosure at every step.

Candidates are clearly informed when they interact with AI-assisted features. Any candidate can request human review at any stage of the process — a right Jobful surfaces explicitly rather than burying in a privacy policy.

GDPR & data rights

Your data. Your rights.

Jobful is a data processor under GDPR — your organization remains the data controller. We give you the tools and documentation to meet your obligations.

Data subject rights we support

  • check_circleRight of access — data subjects can request a full export of their personal data
  • check_circleRight to rectification — inaccurate data corrected on request
  • check_circleRight to erasure — automated deletion workflows with audit confirmation
  • check_circleRight to data portability — exports in JSON or CSV format
  • check_circleRight to restriction — processing restricted while disputes are resolved
  • check_circleRight to object — processing halted on objection, subject to legitimate grounds
  • check_circleNot subject to automated decisions — every AI-assisted decision requires human review and sign-off
Data Processing Agreement. A DPA is available for all customers. Governed by Romanian law and EU GDPR. To lodge a complaint: dataprotection.ro

How to exercise your rights

Email privacy@jobful.io with your request. We respond within 30 days in line with GDPR Art. 12 timelines.

Data exports are provided in JSON or CSV format. Erasure requests include a written confirmation with an audit timestamp.

Candidates interacting with a Jobful-powered hiring process can request human review of any AI-assisted stage by contacting the recruiting organization's privacy contact, which is disclosed in every hiring workflow.

Lawful bases (Art. 6 GDPR)
All processing activities are documented with their lawful basis — consent, legitimate interest, or contract performance — available in the DPA and on request.

Get in touch

Security inquiries & documentation

Security questionnaires, SOC 2 reports, and DPA documentation are available on request. We take all security reports seriously.

security

Security inquiries

Security questionnaires, penetration test summaries, and compliance documentation available under NDA.

mailsecurity@jobful.io
privacy_tip

Privacy & data rights

GDPR data subject requests, DPA execution, and privacy documentation. Responses within 30 days.

mailprivacy@jobful.io
bug_report

Responsible disclosure

Found a vulnerability? We take all reports seriously and respond promptly. Please do not disclose publicly before we've had a chance to investigate.

mailsecurity@jobful.io
Enterprise-ready

Ready to review Jobful for your organization?

We support security reviews, DPA execution, and SOC 2 documentation requests. Book a demo or contact our security team directly.

Email security team