Security and data protection
DeveloperHiring protects company and candidate data with encryption in transit and at rest, GDPR rights for every candidate, a self-service data processing agreement, retention you control, blind review, and SSO and an audit log on Scale.
How is data protected?
Hiring data is sensitive. CVs, code, interview transcripts and notes all describe real people. We treat every piece of it with the same care.
Encryption in transit
Every connection uses TLS. Plain HTTP requests are redirected to HTTPS.
Encryption at rest
Databases, backups and stored files are encrypted on disk.
Isolated code runs
Candidate code runs in a sandbox with no access to other data or the network outside the test.
Least privilege
Staff access to production data is limited, logged and used only for support you ask for.
Hosting in the EU
Data is stored with an infrastructure provider in the European Union.
Backups
Encrypted backups run daily and follow the same retention rules as live data.
How does DeveloperHiring support GDPR?
Your company is the controller of candidate data. We process it for you under a data processing agreement and give candidates direct control over their own data.
Data processing agreement
Team and Scale customers download the DPA themselves from the dashboard. You can read the full text on the DPA page at any time.
Candidate rights
Candidates export or delete their data from the candidate portal, and can opt out of any further contact.
Retention you control
Set how long candidate data stays in your workspace. The default is 12 months, after which data is deleted.
Sourcing from public data only
We use public developer profiles and data candidates give us. Every outreach email has a one-click opt-out.
Lawful basis and notices
Candidates see who processes their data and why, before tests and interviews start.
Processors by category
We use a small number of processors, such as hosting, email delivery, payments and an AI model provider, each under contract.
Read the data processing agreement and the privacy policy.
How do you keep AI scoring fair?
Recruitment AI needs human oversight, clear logs and openness toward candidates. That is how the product is built.
- Blind review. The scoring step never sees name, photo, age or gender. CVs are anonymised before scoring.
- Reasons for every score. Each AI score comes with a written reason your team can check.
- People decide. No candidate is rejected by the system alone.
- Human review on request. Candidates can ask for a person to review any AI score.
- Disclosure. Candidates are told which stages use AI before they start.
More on this for candidates on our AI transparency page.
Blind review on
Name and photo hidden until shortlist
89
overall
Code
92
Interview
83
Integrity
Clean
Changed retention to 9 months
Admin
Exported shortlist CSV for Senior Go engineer
Recruiter
Viewed scorecard of Candidate 2210
Interviewer
Enabled SSO enforcement
Admin
Deleted candidate on request
Recruiter
What does the Scale plan add for security teams?
- Single sign-on. SAML SSO with your identity provider, with optional enforcement for every seat.
- Audit log. Who viewed, exported, changed or deleted what, and when.
- Named contact. Scale accounts get a named contact and priority email support.
- Identity verification. Document and selfie check for candidates, with consent.
- API tokens. Scoped tokens and signed webhooks for your own systems.
- Invoice billing. Pay by card or by invoice.
Compare plans on the pricing page.
Security questions
Ready to see five verified developers for your role?
Paste a role description and get a skill matrix, screening questions and a sample coding task. Plans start at $99 per month billed yearly, with no placement fees.