Your candidate data is sacred. We treat it that way.
RecruitOnline is ISO 27001 certified and built on an enterprise-grade foundation - so your team can move fast without worrying about the stuff underneath.
ISO 27001 certified.
Our information security management system is independently audited. Certificate and Statement of Applicability available on request.
ISO 27001 certified
Information security management system certified since 2022. Surveillance audits annually.
GDPR & UK GDPR
Data-processing agreements and Standard Contractual Clauses available for EU & UK customers.
Australian Privacy Principles
Compliant with the APP and the NZ Privacy Act 2020. Privacy Impact Assessment on request.
CCPA / CPRA
We do not sell or share personal information for advertising.
Hosted on AWS in Sydney, Australia.
The platform runs on AWS in Sydney - primary data, backups and logs stay within that infrastructure. We support customers in four regions; a cross-border notice is available for customers outside Australia.
Australia
- Australian Privacy Principles
- Isolated database per new tenant
- Local support hours
- SEEK & Kudosity native
New Zealand
- NZ Privacy Act 2020 compliant
- Trade Me & Zeil integrations native
- Local account management
- Cross-border notice on request
United Kingdom
- UK GDPR compliant
- DPA available
- SCCs for cross-border transfers
- Hosted in Sydney
United States
- Indeed integration native
- Sub-processor list on request
- Hosted in Sydney
- DPA available
Boring-on-purpose engineering.
Encryption everywhere
AES-256 at rest, TLS 1.2/1.3 in transit.
SSO & MFA
Controlled internal support access. Optional TOTP multi-factor authentication, enabled per user on new-platform accounts. SAML SSO is on the roadmap.
Role-based access
Permissions by role, team, brand or office. Juniors see what they need. Not what they don't.
Audit logging
Logins, user-account changes, API activity and AI screening outcomes are logged with timestamps.
Automated backups
Daily backups with 30-day retention, managed as part of our ISO 27001 controls.
Resilient by design
Multi-AZ architecture on AWS with automated fail-over.
DDoS protection
AWS Shield and a Web Application Firewall filter malicious traffic before it reaches the platform.
Separated environments
Separate VPCs for production, staging and development, with least-privilege IAM roles.
Secure development
Automated static code analysis and peer-review gates on every change, with development aligned to the OWASP Top 10.
Database-per-tenant
Each customer's data lives in its own isolated database - not mixed into shared tables - for true multi-tenant isolation.
Independent security testing
Independent security testing and audits under our ISO 27001 programme, with annual surveillance audits.
Your data isn't AI training fuel
AI features are invoked per request; your candidate and client data is never used to train public AI models.
Who touches the data, and why.
The third-party services that process data on our behalf. Questions about any of them - or changes to this list - are handled through our privacy contact.
| Sub-processor | Purpose |
|---|---|
| Amazon Web Services | Hosting, storage, networking, email delivery |
| Workspace environment, online meetings, analytics | |
| Atlassian | Project management, customer support, knowledge base |
| Stripe | Subscription billing |
| GitHub | Code repository |
| Slack | Internal messaging |
| Kudosity | SMS messaging (primary) |
| Sinch MessageMedia | SMS messaging |
| Xero | Accounting |
| Cloudflare | Website delivery & custom careers-site domains |
| OpenAI | AI features - per-request processing; never used to train public models |
| xAI | AI note capture - per-request processing; never used to train public models |
Need the full pack?
Data Processing Addendum available for e-signature on request. ISO 27001 certificate, Statement of Applicability and SCCs available under NDA.