Skip to content
Surhires

Compliance

The compliance matrix, walked posture by posture

Procurement wants to know who is responsible for what, so every regime here carries an explicit posture rather than a reassuring sentence that answers nothing.

Surhires publishes a compliance matrix rather than compliance claims. Each regime carries one of five postures: supported in product, shared responsibility, customer responsibility, in progress, or not applicable. Nothing on this site states that Soor LLC or Surhires is compliant with, or certified against, any statute. This page walks the whole matrix.

By Surhires Editorial · Published · Reviewed

Why this page is a matrix and not a list of badges

This is a plain-English explanation of where responsibility sits for each obligation a recruitment firm is likely to be asked about. It is not a certification, an audit report or legal advice. The binding documents are your executed agreement, the data processing addendum attached to it, and the policies published on this site as they currently stand. Where this page and those documents differ, those documents govern.

The reason for a matrix is that a badge answers the wrong question. A buyer does not need to know that a vendor cares about compliance. They need to know, for each obligation their own clients will ask about, whether the product does the thing, whether it helps them do the thing, or whether it has nothing to do with the thing at all. Those are three different answers and a badge collapses them into one.

Five postures are used across twelve regimes. Supported in product means the capability exists and the responsibility for using it correctly is still yours. Shared responsibility means the work genuinely splits. Customer responsibility means the product provides fields and integrations but the obligation is entirely yours. In progress means a programme is running and no result is claimed. Not applicable means what it says.

In progress: SOC 2 and WCAG 2.1 AA

SOC 2 readiness is under way with continuous control monitoring. A Type I report is the first deliverable. No Type II report is claimed until one has been issued, and the report date will be published when there is one. A readiness programme is a real thing with real work in it, and it is not a certification. Any vendor page that lets those two blur together is doing so deliberately.

WCAG 2.1 AA is the accessibility target. Candidate-facing surfaces are built to it and audited before each release, and findings and their status are published on the trust page. Conformance is described as a programme rather than a finished state, because every release changes the surface and a one-time claim of full conformance ages badly.

What in progress gives a buyer is a straight answer to the question a security reviewer actually asks: is there a report, and if not, is there a programme with a first deliverable named. Yes to the second, not yet to the first, is a usable answer. A logo implying the first is not.

  • SOC 2: readiness programme running, Type I is the first deliverable
  • No Type II claimed until issued, and the date published when it is
  • WCAG 2.1 AA: candidate surfaces built to it and audited each release
  • Accessibility findings and their status published rather than summarised
  • In progress never rendered as a badge, a shield or an implied certification

Shared responsibility: GDPR, CCPA, DPDP and NYC Local Law 144

For UK and EU GDPR the product supports consent capture on candidate records, configurable retention windows, data export and erasure workflows. You remain the controller for the candidate data you hold, which means the lawful basis, the retention decision and the answer to a data subject are yours. The product makes the controller's job possible; it does not perform the role.

CCPA and CPRA sit the same way: the product supports consumer access, deletion and opt-out request handling against candidate records held in your tenant. India's DPDP Act likewise supports notice and consent records against candidate profiles, and portability export. In each case the tooling is real and the obligation is yours.

NYC Local Law 144 is the sharpest example of a genuine split. Where an automated employment decision tool is in scope, the product records which candidates were scored and exports the data an independent bias audit needs. Commissioning that audit and issuing candidate notice remain yours. Nobody can commission your audit for you, and a vendor claiming to have handled that obligation has misunderstood it.

Supported in product: outreach, recording, EEO, pay transparency and right to work

For TCPA and CAN-SPAM the product supports opt-in capture, STOP and unsubscribe keyword handling, suppression lists and a physical postal address in email footers. Whether a given campaign is lawful depends on how you configure and send it. That sentence is the whole posture in one line, and it is the honest one.

Call recording consent is handled by restricting recording and transcription by jurisdiction, playing a spoken disclosure before recording begins, and applying per-tenant retention limits. All-party-consent states are handled by disabling recording rather than by assuming consent, which is the conservative default and occasionally an inconvenient one.

EEOC and OFCCP reporting is supported by storing demographic data separately from the hiring record, keeping it invisible to recruiters, and using a fixed disposition code list rather than free text so an audit trail can reconstruct the decision. Pay transparency is supported by checking a posting against the salary-range disclosure rules of the states and countries it is published to and flagging it before it goes out. Right to Work, I-9 and Working Rights are supported by document capture and expiry reminders; the verification itself is a workflow you run, not a certification we hold.

  • Opt-in capture, keyword handling, suppression lists and postal footers
  • Jurisdictional recording restrictions with a spoken disclosure before recording
  • Demographic data separated, invisible to recruiters, excluded from model payloads
  • Fixed disposition codes so selection rates can be computed and reviewed
  • Salary-range checks against destination rules before a posting goes out
  • Right to work document capture with expiry reminders on the record

Customer responsibility: 10DLC registration and everything downstream of it

SMS sending in the United States requires your own brand and campaign registration with the carriers. The product provides the fields and the sending integration; the registration is yours. There is no way for a software vendor to hold that registration on your behalf, and a vendor that implies it can is describing something the carriers do not permit.

The same logic runs through the other customer-held items even where they are not separate rows: your WhatsApp Business number and its template approvals, your job board contracts and their terms of use, your background-check vendor relationships and the adverse-action process that goes with them, and your client contracts and whatever they flow down to you.

Naming this category explicitly is the point of the matrix. A buyer who assumes the platform covers registration discovers otherwise when a campaign is blocked, usually on the day it mattered. Reading the customer-responsibility row before signing is considerably cheaper than reading it afterwards.

How to use this in a security review or a client audit

Staffing firms increasingly get audited by their own clients, and the questions arrive as a spreadsheet. The efficient move is to answer each line with the posture and the capability rather than with a yes. Yes invites a follow-up. Supported in product, with these controls, and this part sits with us as the employer or the agency, closes the line.

Where a row says shared responsibility, your answer needs to describe your half. What lawful basis do you rely on, what retention window did you set, who answers a data subject request, who commissions a bias audit if one is in scope. Those answers do not come from the vendor and a reviewer will notice if you try to source them from one.

The documents to have alongside this page are the data processing addendum, the subprocessor register with its version date, the security overview and, when issued, the SOC 2 report. Those four cover most of what a reviewer asks for, and knowing which one answers which question saves a week.

  • Answer audit lines with the posture, not with a bare yes
  • Prepare your half of every shared-responsibility row in advance
  • Keep the versioned subprocessor register with your assessment
  • Have the addendum and security overview to hand before the review starts
  • Do not represent a readiness programme as a completed audit

What is deliberately not claimed anywhere on this site

No page on this site states that Surhires or Soor LLC is compliant with, or certified against, a statute or framework. Not GDPR compliant, not TCPA compliant, not SOC 2 certified. Those phrases are common in recruitment software marketing and they are wrong in a specific way: compliance attaches to a processing operation and a controller, not to a piece of software sitting on a shelf.

Criminal and regulatory statutes are also never described as certifications. There is no such thing as being certified against the TCPA. A product can support the controls a sender needs; whether the sender is lawful depends on consent, registration, content and timing, all of which the sender controls.

The reason for holding this line even where it costs a sentence of marketing polish is that the buyers who care are precisely the buyers worth having. A procurement reviewer who has seen a hundred vendor claims can tell the difference between a capability statement and a badge, and treats the vendor accordingly.

What you get

SOC 2 readiness

Programme under way with continuous control monitoring; a Type I report is the first deliverable.

No Type II claim

Nothing asserted until a report is issued, with the report date published when there is one.

GDPR and UK GDPR support

Consent capture, configurable retention, export and erasure, with you remaining the controller.

CCPA and CPRA support

Consumer access, deletion and opt-out request handling against candidate records in your tenant.

India DPDP support

Notice and consent records against candidate profiles, plus portability export.

TCPA and CAN-SPAM controls

Opt-in capture, STOP and unsubscribe handling, suppression lists and postal address in footers.

10DLC stays with you

Carrier brand and campaign registration is yours; we provide the fields and the sending integration.

Recording consent by jurisdiction

Spoken disclosure before recording, retention limits, and recording disabled in all-party-consent states.

Local Law 144 export

Records which candidates were scored and exports what an independent bias audit needs.

EEO data separation

Demographic data stored apart from the hiring record and invisible to recruiters.

Coded dispositions

A fixed reason list rather than free text, so an audit trail reconstructs the decision.

Pay transparency checks

Postings checked against the salary-range rules of their destinations and flagged before publication.

Right to work capture

Document capture and expiry reminders; the verification workflow remains yours to run.

WCAG 2.1 AA programme

Candidate surfaces built to the standard and audited each release, with findings published.

Questions recruiters ask

Is Surhires SOC 2 certified?

No. A readiness programme is under way with continuous control monitoring, and a Type I report is the first deliverable. No Type II report is claimed until one has been issued, and the date will be published when there is one. A readiness programme is real work, and describing it as a certification would misrepresent what has actually happened.

Why does no page say GDPR compliant?

Because compliance attaches to a processing operation and a controller, not to software. You are the controller of the candidate data you hold, and the outcome depends on your lawful basis, your retention decisions, your training and your recruiters. The product supports consent capture, retention windows, export and erasure. That is a capability statement, and it is the accurate one.

What does shared responsibility mean in practice?

It means the work genuinely splits and both halves have to be done. For NYC Local Law 144, the product records which candidates were scored and exports what an independent bias audit needs; commissioning that audit and issuing candidate notice remain yours. A reviewer will ask you about your half, and no vendor answer covers it.

Can you handle our 10DLC registration?

No. US SMS sending requires your own brand and campaign registration with the carriers, and that registration has to sit with the sending entity. We provide the fields and the sending integration. Any vendor implying it can register on your behalf is describing something the carriers do not allow, and the discovery usually happens mid-campaign.

Our client audit asks for a yes or no per line. What do we write?

Write the posture and the control rather than a bare yes. Supported in product with these specific controls, or shared with our half described, closes a line that a yes would reopen. Keep the data processing addendum, the versioned subprocessor register and the security overview alongside, because those answer most follow-up questions directly.

Does any of this constitute legal advice?

No. This page explains how one vendor has allocated responsibility, in plain English, so a buyer can assess it. Whether that allocation satisfies your obligations depends on your jurisdiction, your entity structure, your client contracts and facts this page cannot see. Those questions belong to counsel who knows your operation, with the executed documents in front of them.

See it against your own reqs

Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.