Welcome to Talent Unlimited's Trust Centre. Explore our compliance posture, the security controls behind the platform, the documents your team needs, and the vendors we work with.
Compliance
Controls
Subprocessors
Resources
Security, compliance, privacy, and legal documentation for Talent Unlimited.
Public Available now
On request A short form
- Information Security Policy
- Access Control Policy
- Incident Response Policy
- Change Management
- Secure SDLC
- Data Retention & Deletion
- Disaster Recovery & Business Continuity
- Acceptable Use Policy
Controls
Summaries of our policies and controls.
No controls match your search.
Infrastructure security13 controls
Data encrypted at rest
The company's databases, cache and file storage are encrypted at rest.
Data encrypted in transit
The company encrypts data transmitted over public networks; no traffic is served in plaintext.
Cloud infrastructure provider utilized
The company hosts production infrastructure with a reputable third-party cloud provider that maintains provider-grade physical security.
Production network segregated
The company isolates production within a private network; internal services such as databases are not reachable from the public internet.
Production OS access restricted
The company restricts privileged access to production operating systems to authorized users with a business need, enforced over VPN with multi-factor authentication.
Infrastructure availability maintained
The company deploys production compute and databases redundantly across multiple availability zones.
Managed cloud services utilized
The company relies on managed cloud services to inherit provider patching and resilience.
Firewall and DDoS protection utilized
The company protects its network edge with a web application firewall and distributed denial-of-service mitigation.
Production environment segregated
The company separates production from development and testing at the infrastructure level, with no shared resources.
Infrastructure monitoring utilized
The company centralizes logging, metrics and alerting, with alerts routed to the engineering team.
Backup processes established
The company automatically backs up production data, encrypts backups, and supports point-in-time recovery.
Encryption key access restricted
The company stores secrets and encryption keys in managed, encrypted stores and restricts access to authorized users with a business need.
Endpoint firewalls configured
The company enables software firewalls on all endpoints and reviews the rules at least quarterly.
Organizational security13 controls
Employee background checks performed
The company performs background checks on new employees, including identity verification and references.
Confidentiality Agreement acknowledged by employees
The company requires employees to sign a confidentiality agreement, and non-disclosure agreements are signed before proprietary information is exchanged.
Security awareness training implemented
The company provides regular security-awareness training to staff, reinforced with quarterly communications.
Mobile device management enforced
The company centrally manages company devices through mobile device management (MDM).
Full-disk encryption enforced
The company enforces full-disk encryption on all company laptops.
Remote device management enabled
The company configures devices to lock automatically on inactivity and can remotely lock or wipe lost or stolen devices.
Password manager utilized
The company provides an enterprise password manager that issues unique, high-entropy credentials to all staff.
Asset inventory maintained
The company maintains a classified inventory of assets and securely disposes of assets by wiping or physical destruction.
Personal device use restricted
The company limits personal devices to approved applications, requires security updates, and prohibits rooted or jailbroken devices.
Approved software enforced
The company permits only vendor-supported, licensed software and reviews installed software regularly.
Anti-malware protection deployed
The company protects all endpoints with supported, automatically updated anti-malware that blocks malicious code on detection.
Security updates applied within 14 days
The company applies critical and high-risk security updates within 14 days of release, with automatic updates enabled where supported.
Security policies reviewed
The company reviews its security policies at least annually and after any material change.
Product security15 controls
Multi-factor authentication enforced
The company enforces multi-factor authentication for administrative and cloud-environment access.
Role-based access control enforced
The company applies least-privilege, role-based access across its systems and platform.
Customer data segregated
The company segregates customer data between tenants at the application and API-permission level.
Password policy enforced
The company enforces length and complexity requirements and rejects common or breached passwords.
Brute-force protection enabled
The company rate-limits authentication attempts per account and per IP address to resist brute-force attacks.
Development lifecycle established
The company follows a secure software development lifecycle, with coding aligned to the OWASP Top Ten.
Change management procedures enforced
The company requires changes to be documented and peer-reviewed on protected branches; authors cannot approve their own changes.
Automated testing performed
The company runs automated tests as required status checks before merge and after deploy.
Production deployment access restricted
The company performs production deployments exclusively through CI/CD, with no manual deploys.
Vulnerability and system monitoring procedures established
The company continuously monitors dependencies for vulnerabilities and maintains supply-chain safeguards.
Release management procedures established
The company verifies releases post-deploy with manual sign-off and maintains rollback and feature-flag capabilities.
Supply-chain install safeguards enforced
The company hardens its build pipeline with a pinned dependency lockfile, disabled package install scripts, and a release-age cooldown before adopting new package versions.
Security reviews conducted at design time
The company reviews security and abuse risks at design time for features that touch personal data, authentication, payments or access control.
Penetration testing performed
The company plans an independent penetration test; internal and AI-assisted testing is performed today.
Static application security testing implemented
The company is introducing additional static application security testing tooling.
Internal security procedures13 controls
Incident response plan established
The company maintains a documented incident response plan with a designated incident response team.
Breach notification procedures established
The company notifies authorities of confirmed breaches within required timeframes.
Post-incident reviews conducted
The company reviews significant incidents and feeds lessons back into its controls.
Change control procedures followed
The company documents, tests and deploys changes in a controlled way that can be rolled back.
Continuity and Disaster Recovery plans established
The company maintains business continuity and disaster recovery plans with defined recovery objectives.
Access reviews conducted
The company reviews access at least every six months and tracks administrator access in a register.
Access revoked upon termination
The company provisions and revokes access through a joiner/mover/leaver process, removing access by the end of the last working day.
Inactive accounts reviewed
The company reviews and disables accounts inactive for more than 90 days.
Segregation of duties enforced
The company separates code authorship from deployment and uses dedicated administrator accounts; authors do not approve their own code.
Audit logging maintained
The company maintains an audit trail across source control, CI/CD, cloud consoles, databases and secret stores.
Compromised account response established
The company maintains a defined response covering suspension, credential reset, token and session revocation, and MFA revalidation.
Third-party security assessments performed
The company assesses a provider's security posture, data scope and contractual terms before adoption, and re-reviews on material change.
Continuity and Disaster Recovery plans tested
The company is establishing annual disaster-recovery testing; the plan is reviewed quarterly today.
Data & privacy14 controls
Privacy program aligned to GDPR
The company aligns its processing with UK GDPR and EU GDPR.
Data retention procedures established
The company maintains a defined retention schedule that automatically deletes or anonymizes data at the end of its retention period.
Data subject requests fulfilled
The company handles access, rectification, erasure, restriction, portability and objection requests within required timeframes.
Human review of automated decisions available
The company allows candidates to request a human review of AI-supported assessments.
Data minimization practiced
The company collects and shares only the data necessary for recruitment.
Records of processing maintained
The company maintains a Record of Processing Activities and a current sub-processor list.
Sub-processor agreements established
The company maintains Data Processing Agreements and contractual safeguards with every sub-processor.
Customer data access restricted
The company restricts access to customer data on a least-privilege basis, logged and reviewed.
Personal data encrypted
The company encrypts personal data at rest and in transit, including backups.
International data transfers safeguarded
The company governs international transfers through recognized mechanisms such as standard contractual clauses.
Privacy notices published
The company publishes a Privacy Policy and Candidate Terms explaining its processing, including opt-out of future-opportunity matching.
Deletion activity logged
The company records deletion operations in an audit log.
Data protection impact assessment conducted
The company has completed a data protection impact assessment for its high-risk AI recruitment processing.
Data protection reviews conducted for changes
The company reviews data-protection implications whenever a change affects how personal data is handled.
AI governance16 controls
Human oversight enforced
The company keeps AI outputs advisory only; recruiters review outputs and can override them.
Pre-production evaluation performed
The company evaluates every prompt and workflow against structured test datasets before production.
Regression testing performed
The company regression-tests every prompt and model change to catch behavioural drift.
Bias and fairness testing conducted
The company tests bias and fairness quarterly and publishes the results.
Enterprise AI providers utilized
The company uses only enterprise-grade AI providers; consumer AI endpoints are never used for candidate processing.
Model training on customer data prohibited
The company contractually prevents customer data from being used to train, tune or improve provider models.
Provider human review prohibited
The company ensures providers do not perform human review of customer prompts, inputs or outputs.
Production prompts governed
The company version-controls and peer-reviews production prompts and restricts them to authorized engineers.
Model output explainability provided
The company presents each output with its rationale and the source material it drew from.
AI activity audited
The company records the prompt version per output and logs overrides and edits.
Data minimization to providers enforced
The company sends only the data necessary for a feature to AI providers.
AI governance aligned to EU AI Act
The company aligns its processing with the EU AI Act and gives advance notice of material AI-provider changes.
Right to contest automated decisions provided
The company allows candidates to contest AI outcomes and request a human review.
Special-category data excluded from evaluation
The company does not use demographic or special-category data in candidate scoring.
Role-specific criteria applied over historical hiring data
The company evaluates candidates against defined role criteria rather than past hiring outcomes.
AI involvement disclosed to candidates
The company discloses where AI is used across the candidate journey.
A green check marks a control we operate today. "In progress" marks a control we're actively building; "Planned" marks one on our roadmap. We hold Cyber Essentials; ISO/IEC 27001 and SOC 2 alignment are on our roadmap. Detailed policies and evidence are available on request.
Subprocessors
The third parties we rely on to run the platform, and what each one does. We give customers advance notice before the list changes.
We answer security questionnaires in days, not weeks.
Send yours over and we'll turn it around fast. Prefer to talk it through? We'll set up a short call.