Trust Centre

Security and trust at Talent Unlimited

Welcome to Talent Unlimited's Trust Centre. Explore our compliance posture, the security controls behind the platform, the documents your team needs, and the vendors we work with.

Controls

Subprocessors

Google Cloud PlatformCloud hosting & AI processing
Amazon Web ServicesStorage, email & DNS
NetlifyFront-end hosting & CDN
DeepgramSpeech-to-text
StripePayment processing

Resources

Security, compliance, privacy, and legal documentation for Talent Unlimited.

On request A short form

  • Information Security Policy
  • Access Control Policy
  • Incident Response Policy
  • Change Management
  • Secure SDLC
  • Data Retention & Deletion
  • Disaster Recovery & Business Continuity
  • Acceptable Use Policy

Request access

Controls

Summaries of our policies and controls.

Infrastructure security13 controls

ControlStatus

Data encrypted at rest

The company's databases, cache and file storage are encrypted at rest.

Data encrypted in transit

The company encrypts data transmitted over public networks; no traffic is served in plaintext.

Cloud infrastructure provider utilized

The company hosts production infrastructure with a reputable third-party cloud provider that maintains provider-grade physical security.

Production network segregated

The company isolates production within a private network; internal services such as databases are not reachable from the public internet.

Production OS access restricted

The company restricts privileged access to production operating systems to authorized users with a business need, enforced over VPN with multi-factor authentication.

Infrastructure availability maintained

The company deploys production compute and databases redundantly across multiple availability zones.

Managed cloud services utilized

The company relies on managed cloud services to inherit provider patching and resilience.

Firewall and DDoS protection utilized

The company protects its network edge with a web application firewall and distributed denial-of-service mitigation.

Production environment segregated

The company separates production from development and testing at the infrastructure level, with no shared resources.

Infrastructure monitoring utilized

The company centralizes logging, metrics and alerting, with alerts routed to the engineering team.

Backup processes established

The company automatically backs up production data, encrypts backups, and supports point-in-time recovery.

Encryption key access restricted

The company stores secrets and encryption keys in managed, encrypted stores and restricts access to authorized users with a business need.

Endpoint firewalls configured

The company enables software firewalls on all endpoints and reviews the rules at least quarterly.

Organizational security13 controls

ControlStatus

Employee background checks performed

The company performs background checks on new employees, including identity verification and references.

Confidentiality Agreement acknowledged by employees

The company requires employees to sign a confidentiality agreement, and non-disclosure agreements are signed before proprietary information is exchanged.

Security awareness training implemented

The company provides regular security-awareness training to staff, reinforced with quarterly communications.

Mobile device management enforced

The company centrally manages company devices through mobile device management (MDM).

Full-disk encryption enforced

The company enforces full-disk encryption on all company laptops.

Remote device management enabled

The company configures devices to lock automatically on inactivity and can remotely lock or wipe lost or stolen devices.

Password manager utilized

The company provides an enterprise password manager that issues unique, high-entropy credentials to all staff.

Asset inventory maintained

The company maintains a classified inventory of assets and securely disposes of assets by wiping or physical destruction.

Personal device use restricted

The company limits personal devices to approved applications, requires security updates, and prohibits rooted or jailbroken devices.

Approved software enforced

The company permits only vendor-supported, licensed software and reviews installed software regularly.

Anti-malware protection deployed

The company protects all endpoints with supported, automatically updated anti-malware that blocks malicious code on detection.

Security updates applied within 14 days

The company applies critical and high-risk security updates within 14 days of release, with automatic updates enabled where supported.

Security policies reviewed

The company reviews its security policies at least annually and after any material change.

Product security15 controls

ControlStatus

Multi-factor authentication enforced

The company enforces multi-factor authentication for administrative and cloud-environment access.

Role-based access control enforced

The company applies least-privilege, role-based access across its systems and platform.

Customer data segregated

The company segregates customer data between tenants at the application and API-permission level.

Password policy enforced

The company enforces length and complexity requirements and rejects common or breached passwords.

Brute-force protection enabled

The company rate-limits authentication attempts per account and per IP address to resist brute-force attacks.

Development lifecycle established

The company follows a secure software development lifecycle, with coding aligned to the OWASP Top Ten.

Change management procedures enforced

The company requires changes to be documented and peer-reviewed on protected branches; authors cannot approve their own changes.

Automated testing performed

The company runs automated tests as required status checks before merge and after deploy.

Production deployment access restricted

The company performs production deployments exclusively through CI/CD, with no manual deploys.

Vulnerability and system monitoring procedures established

The company continuously monitors dependencies for vulnerabilities and maintains supply-chain safeguards.

Release management procedures established

The company verifies releases post-deploy with manual sign-off and maintains rollback and feature-flag capabilities.

Supply-chain install safeguards enforced

The company hardens its build pipeline with a pinned dependency lockfile, disabled package install scripts, and a release-age cooldown before adopting new package versions.

Security reviews conducted at design time

The company reviews security and abuse risks at design time for features that touch personal data, authentication, payments or access control.

Penetration testing performed

The company plans an independent penetration test; internal and AI-assisted testing is performed today.

Planned

Static application security testing implemented

The company is introducing additional static application security testing tooling.

In progress

Internal security procedures13 controls

ControlStatus

Incident response plan established

The company maintains a documented incident response plan with a designated incident response team.

Breach notification procedures established

The company notifies authorities of confirmed breaches within required timeframes.

Post-incident reviews conducted

The company reviews significant incidents and feeds lessons back into its controls.

Change control procedures followed

The company documents, tests and deploys changes in a controlled way that can be rolled back.

Continuity and Disaster Recovery plans established

The company maintains business continuity and disaster recovery plans with defined recovery objectives.

Access reviews conducted

The company reviews access at least every six months and tracks administrator access in a register.

Access revoked upon termination

The company provisions and revokes access through a joiner/mover/leaver process, removing access by the end of the last working day.

Inactive accounts reviewed

The company reviews and disables accounts inactive for more than 90 days.

Segregation of duties enforced

The company separates code authorship from deployment and uses dedicated administrator accounts; authors do not approve their own code.

Audit logging maintained

The company maintains an audit trail across source control, CI/CD, cloud consoles, databases and secret stores.

Compromised account response established

The company maintains a defined response covering suspension, credential reset, token and session revocation, and MFA revalidation.

Third-party security assessments performed

The company assesses a provider's security posture, data scope and contractual terms before adoption, and re-reviews on material change.

Continuity and Disaster Recovery plans tested

The company is establishing annual disaster-recovery testing; the plan is reviewed quarterly today.

Planned

Data & privacy14 controls

ControlStatus

Privacy program aligned to GDPR

The company aligns its processing with UK GDPR and EU GDPR.

Data retention procedures established

The company maintains a defined retention schedule that automatically deletes or anonymizes data at the end of its retention period.

Data subject requests fulfilled

The company handles access, rectification, erasure, restriction, portability and objection requests within required timeframes.

Human review of automated decisions available

The company allows candidates to request a human review of AI-supported assessments.

Data minimization practiced

The company collects and shares only the data necessary for recruitment.

Records of processing maintained

The company maintains a Record of Processing Activities and a current sub-processor list.

Sub-processor agreements established

The company maintains Data Processing Agreements and contractual safeguards with every sub-processor.

Customer data access restricted

The company restricts access to customer data on a least-privilege basis, logged and reviewed.

Personal data encrypted

The company encrypts personal data at rest and in transit, including backups.

International data transfers safeguarded

The company governs international transfers through recognized mechanisms such as standard contractual clauses.

Privacy notices published

The company publishes a Privacy Policy and Candidate Terms explaining its processing, including opt-out of future-opportunity matching.

Deletion activity logged

The company records deletion operations in an audit log.

Data protection impact assessment conducted

The company has completed a data protection impact assessment for its high-risk AI recruitment processing.

Data protection reviews conducted for changes

The company reviews data-protection implications whenever a change affects how personal data is handled.

AI governance16 controls

ControlStatus

Human oversight enforced

The company keeps AI outputs advisory only; recruiters review outputs and can override them.

Pre-production evaluation performed

The company evaluates every prompt and workflow against structured test datasets before production.

Regression testing performed

The company regression-tests every prompt and model change to catch behavioural drift.

Bias and fairness testing conducted

The company tests bias and fairness quarterly and publishes the results.

Enterprise AI providers utilized

The company uses only enterprise-grade AI providers; consumer AI endpoints are never used for candidate processing.

Model training on customer data prohibited

The company contractually prevents customer data from being used to train, tune or improve provider models.

Provider human review prohibited

The company ensures providers do not perform human review of customer prompts, inputs or outputs.

Production prompts governed

The company version-controls and peer-reviews production prompts and restricts them to authorized engineers.

Model output explainability provided

The company presents each output with its rationale and the source material it drew from.

AI activity audited

The company records the prompt version per output and logs overrides and edits.

Data minimization to providers enforced

The company sends only the data necessary for a feature to AI providers.

AI governance aligned to EU AI Act

The company aligns its processing with the EU AI Act and gives advance notice of material AI-provider changes.

Right to contest automated decisions provided

The company allows candidates to contest AI outcomes and request a human review.

Special-category data excluded from evaluation

The company does not use demographic or special-category data in candidate scoring.

Role-specific criteria applied over historical hiring data

The company evaluates candidates against defined role criteria rather than past hiring outcomes.

AI involvement disclosed to candidates

The company discloses where AI is used across the candidate journey.

A green check marks a control we operate today. "In progress" marks a control we're actively building; "Planned" marks one on our roadmap. We hold Cyber Essentials; ISO/IEC 27001 and SOC 2 alignment are on our roadmap. Detailed policies and evidence are available on request.

Subprocessors

The third parties we rely on to run the platform, and what each one does. We give customers advance notice before the list changes.

ProviderPurposeData processed
Google Cloud PlatformCloud hosting, infrastructure and AI processing (Vertex AI / Gemini)Account data, candidate profiles, job and interview data, and AI prompt inputs and outputs
Amazon Web ServicesObject storage, email delivery and DNSUploaded files such as CVs and interview recordings, and transactional email content
NetlifyFront-end hosting and content deliveryStatic frontend assets and basic request metadata
DeepgramSpeech-to-text transcriptionInterview audio and the resulting transcripts
Google Speech servicesSpeech-to-text and text-to-speechInterview audio, transcripts and voice-synthesis prompts
Google Places APILocation autocompleteFree-text location queries typed by users; no precise device location is collected
StripePayment processingBilling contact and subscription details; card data goes directly to Stripe
TwilioSMS notificationsRecipient phone numbers and message content
SentryApplication error monitoringError and performance diagnostics, including request metadata
LogRocketSession diagnostics and supportFrontend session recordings and client-side errors, with sensitive fields masked
MezmoApplication log aggregationBackend application logs, which may include account identifiers and request metadata
Google AnalyticsWeb analyticsPseudonymous usage data: truncated IP, device and browser details, and page interactions
SlackInternal operational notificationsTeam notification content and account identifiers
Google WorkspaceBusiness productivity and collaborationStaff correspondence and stored documents, including exported reports

We answer security questionnaires in days, not weeks.

Send yours over and we'll turn it around fast. Prefer to talk it through? We'll set up a short call.

Email our security team

Request document access

Tell us who you are and we'll share the documents you need.