1. Our approach
The Scrini Agentic Hiring OS is built for enterprise hiring. We apply defense in depth across people, processes, applications and infrastructure, and collect only the data needed to do the job. Our security controls are mapped to SOC 2 and ISO 27001.
2. Hosting and data residency
The Service runs on Amazon Web Services in the Mumbai (India) and Frankfurt (Germany) regions. Customers can choose EU-only hosting. Our Subprocessors page lists the third parties that process customer data.
3. Encryption
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Webhook payloads are signed with secrets customers can rotate.
4. Identity and access
We support SSO with SAML 2.0, SCIM provisioning, MFA, role-based and attribute-based access control, enforced session expiry and IP allow-listing. Internal access follows least privilege and is reviewed regularly.
5. Network security
Production runs in private VPCs with subnet isolation, a web application firewall, DDoS mitigation and egress controls.
6. Application security
We follow a secure development lifecycle with peer code review, dependency scanning, static and dynamic testing and separate environments for development, testing and production.
7. AI safeguards
Customer candidate data is used only for that customer's hiring and is never used to train or fine-tune shared AI models. Each customer's data is kept separate from other customers' data. Third-party providers that process customer data for AI features are subprocessors bound by data processing terms, as described on our Subprocessors page.
8. People
Everyone at Scrini completes security and privacy training. People with production access are background checked and sign confidentiality agreements, and access is removed immediately when they leave.
9. Vendors
We assess the security and privacy of vendors before using them and bind them with data processing terms, including Standard Contractual Clauses and the UK Addendum where needed.
10. Monitoring and logging
Logs are collected centrally and monitored for anomalies, with 24/7 on-call alerting. Every build is scanned for vulnerabilities, dependencies are checked weekly and infrastructure-as-code is scanned for misconfigurations.
11. Testing
Independent third parties run penetration tests at least once a year and findings are tracked to closure. Executive summaries are available under NDA.
12. Backups and continuity
Backups are encrypted and kept on a 35-day cycle, after which they are deleted. Enterprise customers can agree specific recovery commitments in their contract.
13. Incident response and breach notification
We follow a documented incident response process: detect, contain, eradicate, recover and review. If a confirmed incident affects personal data, we notify affected customers without undue delay and within 72 hours of confirming it, with the scope, impact and the steps we are taking.
14. Controls customers manage
Customers can set custom roles and permissions, mask personal fields, enforce SSO and MFA, set session lifetimes and IP allow-lists, configure retention windows, export and delete data, export audit logs and rotate webhook secrets.
15. Assessment integrity and privacy
Liveness Verify and Pixel-Native help confirm that the person being assessed is the candidate and that they are working without unauthorized help. Liveness Verify masks identifiers on the candidate's device before data leaves it. Data from these checks is used only to check the integrity of the session, is shown to the employer's team for review and follows the same retention and deletion rules as other candidate data.
16. Reporting a vulnerability
If you find a potential vulnerability, please report it as described in our Vulnerability Disclosure policy or email support@scrini.ai with "Security" in the subject. Do not access, change or delete data that is not yours.
17. Security reviews
Customers and prospects can request security documentation, including penetration test executive summaries under NDA. Email support@scrini.ai or book a security review.

