# Fast hiring. Zero shortcuts on security.

> Encryption, SSO, audit trails and data residency. How Scrini keeps candidate data safe and your AI hiring fair and explainable.

URL: https://landing.qa.scrini.ai/security  
Breadcrumb: Home > Security & trust

Your candidates trust you with their data. Here is exactly how we protect it, so your IT, legal and procurement teams can say yes quickly.

[Book a security review](https://cal.id/team/product-demo-scrini-team/product-walkthrough) · [Contact us](https://landing.qa.scrini.ai/contact)

## Your data stays yours.

Candidate data is used only for your own hiring. It is never used to train or fine-tune shared AI models.

You choose where it lives, including EU-only hosting, and you can export or delete it whenever you need to.

## Built in, not bolted on.

### Encryption

TLS 1.3 in transit and AES-256 at rest. Always on, nothing to configure.

### Access control

SSO with SAML 2.0, SCIM provisioning, MFA and role-based permissions. IP allow-listing if you need it.

### Monitoring

Central logging with 24/7 alerting. Every build is scanned and third parties test us independently.

### Your controls

Set retention windows, mask personal fields, export audit logs and rotate webhook secrets yourself.

### Fair and explainable AI

Speed means nothing if you cannot explain a decision. Every candidate for a role gets the same questions and the same scorecard. Every score comes with the evidence behind it. Candidates are told when they are speaking with an AI, and every interaction is recorded with a full transcript.

### If something goes wrong

We follow a documented process: detect, contain, fix, recover and review. If an incident affects personal data, we tell you without undue delay and within 72 hours of confirming it.

### Who we work with

Our infrastructure runs on AWS. Calls, email and SMS run through providers such as Twilio, and AI voice runs through providers such as ElevenLabs when enabled. The full sub-processor list is available on request.

## Security questions

### Do you use our data to train AI?

No. Your data powers your own hiring workflows only. It is never used to train or fine-tune shared AI models.

### Is Scrini SOC 2 or ISO 27001 compliant?

Our security controls are mapped to SOC 2 and ISO 27001, with encryption in transit and at rest. Talk to us for the details your security review needs.

### Where is data hosted?

Data is hosted on AWS in the Mumbai and Frankfurt regions. EU-only hosting is available if you need your data to stay in the EU.

### Do you support SSO?

Yes. SAML 2.0 SSO with SCIM provisioning, MFA, role-based permissions and IP allow-listing if you need it.

### How is candidate data protected?

TLS 1.3 in transit and AES-256 at rest, central logging with 24/7 alerting, scans on every build and independent third-party penetration tests. You can set retention windows, mask personal fields and export or delete data.

### What happens if there is a security incident?

We follow a documented process: detect, contain, fix, recover and review. If an incident affects personal data, we tell you without undue delay and within 72 hours.

### How do we report a vulnerability?

See our vulnerability disclosure page or email support@scrini.ai with "Security" in the subject line.

## Security questions? Let's walk your team through it.

[Book a security review](https://cal.id/team/product-demo-scrini-team/product-walkthrough) · [Contact us](https://landing.qa.scrini.ai/contact)
