Security & Trust

Your candidates' data is the product we protect hardest.

A hiring platform holds compensation data, employment histories, and people quietly looking for their next role. Here's exactly how DSO Hire is built to protect all three, and an honest account of what's still on the roadmap.

Row-level security on every table

Access control is enforced in the database itself, not just the application. Every query a user runs is filtered by Postgres row-level security policies, so a recruiter physically cannot read another organization's data, even if application code had a bug. Server-side permission checks sit on top as a second layer.

Encrypted in transit and at rest

All traffic is TLS-encrypted. Data is encrypted at rest on our database infrastructure (Supabase / AWS). Payments are processed entirely by Stripe; card numbers never touch our servers.

Candidate anonymity, architecturally

Anonymous mode masks a candidate's name and photo from every employer they haven't applied to, enforced by shared masking helpers on every discovery surface, not page-by-page goodwill. Private-practice affiliations are masked in every candidate-facing email and page by the same rule.

The EEO firewall

Voluntary EEO self-identification data is stored in a separate table with NO employer read path: not a hidden one, a nonexistent one. Hiring decision-makers cannot see individual demographic data on this platform, by construction. This mirrors EEOC/OFCCP guidance.

Per-teammate permissions + audit log

Owners and admins tune exactly what each teammate can see and do (down to hiding compensation fields) and can restrict sensitive searches to named people. Role changes, permission grants, offers, and exports are recorded in an audit log.

MFA + session controls

Two-factor authentication is available to every account and can be required organization-wide by the owner. Sensitive surfaces re-verify; trusted devices are scoped and expire.

Infrastructure

DSO Hire runs on Vercel (application) and Supabase on AWS (Postgres database, authentication, file storage) with automated backups. Email is delivered through Resend with per-category one-click unsubscribe. Our AI features run on Anthropic's Claude models with spend circuit-breakers; AI features read your data to answer questions; your data is not used to train models.

Your data, your call

Owners can export their organization's complete data or delete the organization outright from Settings, no support ticket required. We don't sell candidate data, we don't broker resumes, and candidates can delete their accounts and data themselves.

The Honest Part

What we don't have yet, and when we will.

  • SOC 2 Type IIPlanned. Engagement begins alongside our first Enterprise deployments.
  • Third-party penetration testScheduled within 60 days of public launch; summary available to customers under NDA.
  • BAA / HIPAA-aware postureOn the Enterprise roadmap. Note: DSO Hire processes hiring data, not patient PHI.

Security questions, disclosure reports, or due-diligence requests: info@dsohire.com. We answer fast and we don't bluff.

Bring your compliance team.

We'd rather answer the hard questions before you buy than after. Walk the platform with whoever signs off on vendors.

Talk To Us