# Data Security Policy.

> How Scrini AI protects customer and candidate data: encryption, access control, hosting, monitoring, testing, incident response and customer controls.

URL: https://landing.qa.scrini.ai/data-security-policy  
Breadcrumb: Home > Data Security Policy

Last updated: October 2, 2026. How Scrini AI protects customer and candidate data, across people, processes, applications and infrastructure.

## Summary

- Security controls are mapped to SOC 2 and ISO 27001.
- Data is encrypted in transit with TLS 1.3 and at rest with AES-256.
- Data is hosted on AWS in Mumbai and Frankfurt, and EU-only hosting is available.
- Independent third parties test our security at least once a year.
- If an incident affects personal data, we notify affected customers without undue delay and within 72 hours of confirming it.

## 1. Our approach

The Scrini Agentic Hiring OS is built for enterprise hiring. We apply defense in depth across people, processes, applications and infrastructure, and collect only the data needed to do the job. Our security controls are mapped to SOC 2 and ISO 27001.

## 2. Hosting and data residency

The Service runs on Amazon Web Services in the Mumbai (India) and Frankfurt (Germany) regions. Customers can choose EU-only hosting. Our Subprocessors page lists the third parties that process customer data.

## 3. Encryption

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Webhook payloads are signed with secrets customers can rotate.

## 4. Identity and access

We support SSO with SAML 2.0, SCIM provisioning, MFA, role-based and attribute-based access control, enforced session expiry and IP allow-listing. Internal access follows least privilege and is reviewed regularly.

## 5. Network security

Production runs in private VPCs with subnet isolation, a web application firewall, DDoS mitigation and egress controls.

## 6. Application security

We follow a secure development lifecycle with peer code review, dependency scanning, static and dynamic testing and separate environments for development, testing and production.

## 7. AI safeguards

Customer candidate data is used only for that customer's hiring and is never used to train or fine-tune shared AI models. Each customer's data is kept separate from other customers' data. Third-party providers that process customer data for AI features are subprocessors bound by data processing terms, as described on our Subprocessors page.

## 8. People

Everyone at Scrini completes security and privacy training. People with production access are background checked and sign confidentiality agreements, and access is removed immediately when they leave.

## 9. Vendors

We assess the security and privacy of vendors before using them and bind them with data processing terms, including Standard Contractual Clauses and the UK Addendum where needed.

## 10. Monitoring and logging

Logs are collected centrally and monitored for anomalies, with 24/7 on-call alerting. Every build is scanned for vulnerabilities, dependencies are checked weekly and infrastructure-as-code is scanned for misconfigurations.

## 11. Testing

Independent third parties run penetration tests at least once a year and findings are tracked to closure. Executive summaries are available under NDA.

## 12. Backups and continuity

Backups are encrypted and kept on a 35-day cycle, after which they are deleted. Enterprise customers can agree specific recovery commitments in their contract.

## 13. Incident response and breach notification

We follow a documented incident response process: detect, contain, eradicate, recover and review. If a confirmed incident affects personal data, we notify affected customers without undue delay and within 72 hours of confirming it, with the scope, impact and the steps we are taking.

## 14. Controls customers manage

Customers can set custom roles and permissions, mask personal fields, enforce SSO and MFA, set session lifetimes and IP allow-lists, configure retention windows, export and delete data, export audit logs and rotate webhook secrets.

## 15. Assessment integrity and privacy

Liveness Verify and Pixel-Native help confirm that the person being assessed is the candidate and that they are working without unauthorized help. Liveness Verify masks identifiers on the candidate's device before data leaves it. Data from these checks is used only to check the integrity of the session, is shown to the employer's team for review and follows the same retention and deletion rules as other candidate data.

## 16. Reporting a vulnerability

If you find a potential vulnerability, please report it as described in our Vulnerability Disclosure policy or email support@scrini.ai with "Security" in the subject. Do not access, change or delete data that is not yours.

## 17. Security reviews

Customers and prospects can request security documentation, including penetration test executive summaries under NDA. Email support@scrini.ai or book a security review.

## Related policies.

### Privacy Policy

How Scrini collects, uses and protects personal data.

[Read](https://landing.qa.scrini.ai/privacy-policy)

### Candidate Privacy Notice

For people assessed through Scrini by an employer.

[Read](https://landing.qa.scrini.ai/candidate-privacy-notice)

### AI Transparency Notice

How our AI agents work and the choices candidates have.

[Read](https://landing.qa.scrini.ai/ai-transparency)

### Cookie Policy

Cookies, consent and how to change your choices.

[Read](https://landing.qa.scrini.ai/cookie-policy)

### Terms of Service

The agreement for using the Scrini platform.

[Read](https://landing.qa.scrini.ai/terms-of-service)

### Acceptable Use Policy

What customers may and may not do with Scrini.

[Read](https://landing.qa.scrini.ai/acceptable-use-policy)

### Data Processing Addendum

Key terms for processing personal data on your behalf.

[Read](https://landing.qa.scrini.ai/dpa)

### Subprocessors

Third parties that process data for Scrini.

[Read](https://landing.qa.scrini.ai/subprocessors)

### Refund Policy

Credits, billing disputes and refunds.

[Read](https://landing.qa.scrini.ai/refund-policy)

### Accessibility Statement

Our accessibility commitment and accommodations.

[Read](https://landing.qa.scrini.ai/accessibility)

### Vulnerability Disclosure

How to report a security issue.

[Read](https://landing.qa.scrini.ai/vulnerability-disclosure)
