SecurityTrust posture

Built to keep your recruiting data safe.

Vitae handles candidate data, personal information, and sometimes salary and right-to-work documents. We treat security as a first-class product surface, not a checkbox.

01Compliance/ certifications

Frameworks we hold or are actively working toward.

SOC 2
Type II audit in progress. Status updated quarterly.
GDPR
Compliant by default. DPA available on request.
EEO
Anonymous demographic capture, audit-ready reporting.
ISO 27001
On the roadmap for 2026.
02How we protect data/ six pillars

How we actually protect your data.

The controls behind the certifications. Plain language, no marketing hand-waving.

01

Encryption

All data encrypted at rest with AES-256 and in transit with TLS 1.3. Key rotation policies aligned with industry best practice.

02

Hosted on Google Cloud

EU and US regions available. Pinned to your chosen region for the lifetime of your workspace. Enterprise customers can request specific zones.

03

Audit logs

Every read and write is logged with actor, timestamp, and payload. Retention is 12 months by default, longer on request.

04

Single sign-on

SSO via Okta, Google Workspace, Microsoft Entra ID, and any SAML 2.0 provider. Available on Scale tier and above.

05

Granular permissions

Per-workspace, per-pipeline, per-record access control. Define what each role can see and change. Admin override on every action.

06

Right to be forgotten

Complete candidate data deletion on request, with verifiable proof. GDPR Article 17 compliant by default.

03Responsible disclosure/ how to reach us

Found something? Tell us.

We run a private bug bounty program. Email hello@vitae.ai with a description and reproduction steps. Acknowledged within 24 hours, triaged within 72.

04Security FAQ/ six questions

Common security questions.

Answers to the questions buyers, infosec, and procurement teams ask before signing.

Google Cloud. EU (Belgium) and US (Iowa) regions are available today. Each customer's data is logically isolated in its own database schema. Data does not cross regions without explicit customer instruction.

Move recruiting to a platform that takes security seriously.

GDPR by default. SOC 2 in progress. Encryption, audit logs, and data residency on every plan.

Start for freeContact security