Trust
Where responsibility sits for every regime that touches recruitment
A procurement reader needs to know which controls the product provides and which obligations stay with you. This page states both, regime by regime.
The Surhires trust center lists each regime that touches recruitment data with an explicit posture: supported in product, shared responsibility, customer responsibility, in progress, or not applicable. Nothing here is a certification claim. It also covers data residency, the subprocessor register, subject access and erasure, and how to request documentation.
By Surhires Editorial · Published · Reviewed
How to read the posture labels
Compliance is not a property of software. It is a property of how an organisation operates, and software either gives you the controls and records a compliant operation needs or it does not. So every row on this page carries a posture that says where the obligation actually sits, and no row claims a certificate.
The five labels mean specific things, and the difference between them is the difference between a control you can rely on and an obligation you have to staff. Read them before reading the matrix.
- Supported in product: the control exists in Surhires and you can configure and evidence it here
- Shared responsibility: the product provides the mechanism, you remain accountable for the decision and the legal basis
- Customer responsibility: the obligation is yours; we provide fields or an integration but hold nothing on your behalf
- In progress: work is under way and no completed artefact exists yet; the row says what the first deliverable is
- Not applicable: the regime does not apply to the product as scoped, and the row says why rather than staying silent
Security assurance and accessibility
Two rows sit in progress, and both are stated as programmes rather than as achievements. Neither will be upgraded on this page before the artefact exists.
The SOC 2 row is the one procurement teams read first, so the wording is deliberately narrow. A Type I report describes control design at a point in time; a Type II report describes operating effectiveness over a period. Only the first is being pursued now, and the second is not claimed until it is issued.
- SOC 2 Type II - In progress: Readiness programme under way with continuous control monitoring. A Type I report is the first deliverable; we do not claim a Type II report until one has been issued and we will publish the report date when it is.
- WCAG 2.1 AA - In progress: Candidate-facing surfaces are built to WCAG 2.1 AA and audited before each release. Findings and their status are published on the trust page.
Data protection regimes
Every data protection regime that applies to a recruitment database sits in shared responsibility, and that is not an evasion. You decide which candidates to hold, why, and for how long; you are the controller. The product supplies consent records, retention windows, export and erasure so that those decisions can be evidenced and acted on rather than argued about.
The practical consequence is that a subject access request is answerable from the record instead of assembled by hand across a database, an inbox and a shared drive. That is the part most firms fail on, and it is a systems problem rather than a policy problem.
- GDPR and UK GDPR - Shared responsibility: The product supports consent capture on candidate records, configurable retention windows, data export and erasure workflows. You remain the controller for the candidate data you hold.
- CCPA / CPRA - Shared responsibility: Supports consumer access, deletion and opt-out request handling against candidate records held in your tenant.
- India DPDP Act - Shared responsibility: Supports notice and consent records against candidate profiles and portability export.
Outreach, messaging and call recording
Outbound is where recruitment firms take on the most regulatory risk and where vendors are most tempted to write a compliance declaration. The rows below say what the product does and then say plainly which part of the exposure remains yours.
The 10DLC row is the clearest example. US SMS sending requires brand and campaign registration with the carriers under your own name. No vendor can register on your behalf and any that implies otherwise is describing a workflow it does not control.
- TCPA and CAN-SPAM (US) - Supported in product: Supports opt-in capture, STOP and unsubscribe keyword handling, suppression lists and a physical postal address in email footers. Whether a given campaign is lawful depends on how you configure and send it.
- 10DLC registration (US SMS) - Customer responsibility: SMS sending requires your own brand and campaign registration with the carriers. We provide the fields and the sending integration; the registration is yours.
- Call recording consent - Supported in product: Recording and transcription can be restricted by jurisdiction, with a spoken disclosure played before recording begins and per-tenant retention limits. All-party-consent states are handled by disabling recording rather than by assuming consent.
Hiring decisions, fairness and eligibility
Automated scoring in hiring is regulated in a way that most software categories are not, and the regulation is arriving unevenly by city and state. The product's job is to record what happened in enough structure that an independent audit can be run and a decision can be reconstructed. Commissioning that audit, issuing candidate notice and defending the decision remain the employer's obligations.
The design consequence runs through the whole product: demographic data is stored away from the hiring record so it cannot influence a decision it exists to measure, and dispositions are a fixed list rather than free text so a reviewer sees a decision code instead of a recruiter's shorthand.
- NYC Local Law 144 (AEDT) - Shared responsibility: Where an automated employment decision tool is in scope, the product records which candidates were scored and exports the data an independent bias audit needs. Commissioning the audit and issuing candidate notice remain yours.
- EEOC and OFCCP reporting - Supported in product: Demographic data is stored separately from the hiring record and is not visible to recruiters. Disposition codes are a fixed list rather than free text so an audit trail reconstructs the decision.
- Pay transparency laws - Supported in product: A job posting can be checked against the salary-range disclosure rules of the states and countries it is published to, and flagged before it goes out.
- Right to Work / I-9 / Working Rights - Supported in product: Document capture and expiry reminders against the candidate record. The verification itself is a workflow you run, not a certification we hold.
Data residency
The primary region is AWS us-east-1, with encrypted backups. That is the honest current state and it is written here rather than left for a security review to discover.
If your organisation requires that candidate data remain in the European Union, the United Kingdom or Australia, raise it before contract. Regional residency is a scoping conversation, not a settings toggle, and it interacts with the subprocessor list: a model provider, a transcription service or a messaging gateway may operate in a different region from the database, and a residency assessment that ignores those is incomplete.
Where a regional requirement cannot be met, the answer will be that it cannot be met. That is more useful to a data protection officer than a qualified yes.
The subprocessor register
Surhires relies on other providers to send messages, post jobs, place and transcribe calls, run model inference and take payment. Each of those processes some category of customer data, and each is named in the published subprocessor register with what it handles and where it operates.
Additions are notified rather than absorbed into a terms update. The register is the document to attach to a data protection impact assessment, and it is written to be usable for that purpose: one row per provider, the processing purpose, the data categories and the operating region, without marketing language in between.
Subject access, portability and erasure
A candidate has the right to ask what you hold, to receive it in a portable form and, in most cases, to have it deleted. In a typical agency those requests are answered by hand and answered badly, because the data is spread across a database, an email client, a spreadsheet and a folder of attachments.
In Surhires, access, export and erasure are workflows rather than support tickets. An export produces the full record - profile, structured fields, parsed resume text, uploaded files, messages and activity - as CSV or JSON. An erasure removes the profile, the parsed text, the files and the messages and records that the request was fulfilled and when. Financial records tied to a completed placement are retained where law requires it, and the workflow says so rather than quietly keeping everything.
- Consent basis, capture date and channel stored on the candidate record
- Configurable retention windows with dormant records flagged for review or erasure
- Full record export as CSV or JSON, including files and message history
- Erasure that leaves no orphaned copies and logs that the request was fulfilled
Requesting documentation
The data processing agreement, the privacy notice, the cookie policy and the subprocessor register are published under the legal section and can be attached to a procurement file without asking anyone. Regime-specific notes for GDPR, CCPA, the DPDP Act, EEO and OFCCP reporting, and TCPA and CAN-SPAM are published alongside them.
Anything not published - security questionnaire responses, entity documentation, the penetration test summary once it exists - is sent on request through the sales address. Questionnaires are answered directly, including where a control is not yet in place, in which case the response says so and gives a timeline. A questionnaire answered optimistically becomes a contract dispute later, which serves nobody.
What you get
Five explicit postures
Every regime carries supported, shared, customer, in progress or not applicable rather than a vague badge.
SOC 2 stated honestly
Readiness programme with continuous control monitoring; Type I first, no Type II claimed until issued.
WCAG 2.1 AA programme
Candidate-facing surfaces audited before each release, with findings and status published.
Controller boundary stated
Data protection rows say plainly that you remain the controller for the candidate data you hold.
Consent records
Consent basis, capture date and channel stored on the candidate record rather than assumed.
Retention windows
Configurable per tenant, with dormant records flagged for review or erasure on schedule.
Opt-out machinery
STOP and unsubscribe keyword handling, suppression lists and a postal address in email footers.
10DLC boundary
Carrier brand and campaign registration is yours; we supply the fields and the sending integration.
Jurisdictional recording rules
All-party-consent states handled by disabling recording rather than by assuming consent.
Bias-audit export
Records which candidates an automated tool scored and exports what an independent audit needs.
Demographic separation
Equal-opportunity data kept apart from the hiring record and invisible to recruiter roles.
Fixed disposition codes
A closed list rather than free text so an audit trail can reconstruct why a candidate was rejected.
Pay-range validation
A posting is checked against disclosure rules for its target states and countries before it goes out.
Published residency
Primary region named, with regional requirements treated as scope rather than a settings toggle.
Subprocessor register
One row per provider with processing purpose, data categories and operating region.
Subject request workflows
Access, portable export and erasure run as product workflows rather than as support tickets.
Questions recruiters ask
Is Surhires GDPR compliant?
That is not a claim any software vendor can make on your behalf. The posture is shared responsibility: the product supports consent capture on candidate records, configurable retention windows, data export and erasure workflows, and you remain the controller for the candidate data you hold. Compliance depends on how you configure and operate it.
What does shared responsibility actually mean in practice?
It means the mechanism exists here and the accountability stays with you. Surhires can record consent, enforce a retention window and run an erasure, but it cannot decide whether you had a lawful basis to hold a candidate in the first place. The row tells you which half you are looking at so nothing falls between the two.
Can we send SMS to US candidates through Surhires?
You can, once your own 10DLC brand and campaign registration is in place with the carriers. That registration is a customer responsibility and cannot be done by a vendor on your behalf. Surhires provides the fields and the sending integration, plus opt-in capture, STOP handling and suppression lists on the outbound side.
Does Surhires perform the bias audit required by NYC Local Law 144?
No. Where an automated employment decision tool is in scope, the product records which candidates were scored and exports the data an independent bias audit needs. Commissioning that audit and issuing candidate notice remain yours. A vendor that offers to audit its own scoring is not providing the independence the law asks for.
Where is data stored, and can you hold it in the EU or UK?
The primary region is AWS us-east-1 with encrypted backups. Regional residency in the EU, UK or Australia is a scoping conversation to have before contract rather than a toggle, and it interacts with the subprocessor list because a model or messaging provider may operate elsewhere. If a requirement cannot be met, you will be told that.
How do we get your security questionnaire responses?
Ask through the sales address and flag it early, ideally when booking a demo, so documentation is prepared before the first call. Published artefacts - the DPA, privacy notice, cookie policy and subprocessor register - can be downloaded without asking. Questionnaires are answered directly, including where a control is not yet in place.
Will this page change when a certification is issued?
Yes, and it will change by adding a date rather than by softening the language. When a SOC 2 Type I report is issued the report date is published; a Type II report is not referenced until one exists. The same applies to the independent penetration test and tenant-boundary review being commissioned before general availability.
Keep reading
- The engineering answer to how your candidate data is protected
- The compliance matrix, walked posture by posture
- The subprocessor register, and why recruitment needs one
- What the processor agreement commits us to, clause by clause
- Holding candidate data lawfully under UK and EU GDPR
- What California consumers can ask of a recruitment database
- Who builds Surhires, and how we talk about it
- How to reach a person about Surhires
See it against your own reqs
Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.