The version that matters
We hold candidate CVs, career histories and compensation data, and business contacts for our clients. It lives on managed cloud platforms — we run no servers of our own — behind enforced multi-factor authentication, managed laptops, and least-privilege access. We do not hold ISO 27001 or SOC 2 certification, and we won’t imply we do. What we do hold is a documented control set, independently certified core platforms, and a straight answer to every question on your questionnaire. The rest of this page is the detail.
01 Where we stand
Most vendor security pages are written to avoid saying anything. This one is written to save you three weeks.
Recruise is an executive search and talent intelligence firm. If you are evaluating us, your security or procurement team will want to know what we hold, where it sits, who can reach it, and what happens when something breaks. Those answers are below, in the order they are usually asked.
We do not hold ISO/IEC 27001 or SOC 2 certification. We would rather you learned that here, from us, in the first minute — alongside what we do instead — than in week three of an assessment. What we offer in its place:
- Our core platforms — Microsoft 365, which holds our email and documents, and Zoho — are independently certified to ISO/IEC 27001 and SOC 2. Those certifications do real work in our control set, because we operate no infrastructure of our own.
- A pre-answered control questionnaire covering the domains those standards assess — sent on request, usually the same week.
- A documented policy set: access control, data classification and retention, incident response, business continuity, vulnerability management, change control, third-party risk, and privacy by design.
- Configuration evidence — policy settings, access controls, training records — released to a named assessor under NDA.
02 What we hold, and for whom
| Data | Whose | Where it lives |
|---|---|---|
| CVs, career history, compensation, interview notes | Candidates | Applicant tracking system, Microsoft 365 |
| Contacts, mandate briefs, commercial terms | Client organisations | CRM, Microsoft 365 |
| Email address and preferences | Newsletter subscribers | Newsletter platform |
| Files, mail, documents | All of the above | Microsoft 365 |
We act as a Data Processor for personal data you supply and we process on your instruction, and as a Data Fiduciary / Controller for candidate data we source ourselves. Which of those applies changes who answers a data-subject request, so we are precise about it — see our Privacy Policy.
We do not hold payment card data, health records or government identity numbers as a matter of course. Where a mandate genuinely requires sensitive data — immigration status for a relocation role, for example — it is collected with explicit consent, for that mandate only.
We do not sell personal data. We do not run advertising networks on it. We do not use client or candidate data to train external AI models, and we do not put it into public AI services.
03 Where it is processed
All processing takes place in India, by Recruise personnel based in Bengaluru, on company-issued managed devices. The cloud platforms listed in section 06 store data in their own data centres; we will confirm the region for any of them on request.
If your engagement requires India-only residency for your data, tell us before it starts and we will confirm the configuration in writing.
04 How we are built
This is the fact that shapes everything else: Recruise operates no infrastructure of its own. No data centre. No servers. No self-managed databases. No corporate network beyond office internet connectivity.
That is a deliberate design choice, not a gap. It means there is no unpatched server to compromise, no misconfigured database to expose, and no perimeter to breach. It also means our security model is built on three things rather than on a firewall:
- Identity
- A single identity provider with enforced multi-factor authentication and least-privilege, role-based access. Every action is attributable to a named individual — we use no shared or generic accounts.
- Devices
- Client data is processed only on company-issued, centrally managed laptops with endpoint detection and response and application control.
- Vendor selection
- Because the platforms hold the data, choosing and monitoring them is one of our principal security controls — not an administrative afterthought. See section 06.
We describe our controls by what they do rather than by which product delivers them. Naming our specific security tooling publicly would tell an attacker what to work around, and tells you nothing useful about whether the control is effective. Product-level detail is available to a named assessor under NDA.
05 The controls
| Domain | What is in place |
|---|---|
| Identity & access | Single identity provider. Unique named accounts, no shared credentials. MFA enforced on the primary business platform and on all administrative access. Least-privilege, role-based. Administrative rights separated from standard accounts and held by two roles. |
| Joiners & leavers | Access provisioned on start, revoked on the last working day by authorised roles only. Access reviewed periodically by management; inactive accounts disabled when identified. |
| Devices | Company-issued managed laptops only. Endpoint detection and response on every device. Application control preventing unapproved software. No local administrator rights. Automatic screen lock. |
| Data in transit | TLS 1.2 or higher across platform and application traffic, and for email between mail gateways. Where a client needs a forced-TLS mail route, we can set one up — ask during onboarding. |
| Data at rest | Held on managed platforms that encrypt at rest under their own certified controls. No self-managed storage. |
| Data loss prevention | Policies detect and alert on unauthorised transfer of sensitive data across email and cloud storage, centrally monitored. |
| Blocked channels | Personal email, personal social networking, external instant messaging and removable media blocked on managed devices. One approved storage service; one approved messaging tool. |
| Monitoring | Platform audit logging records user and administrator activity. Security alerts feed a single escalation path with defined response. |
| People | Background checks before joining. Confidentiality obligations signed, surviving employment. Security and data-protection training at onboarding and annually, including phishing simulation. |
| Change control | Administrative changes are restricted to two authorised roles. Website changes go through version control and an automated build check before release. |
| Classification | All client data is treated as Confidential by default. Where you operate your own classification scheme, we adopt yours for your data and apply the stricter handling rule. |
06 Our sub-processors
This is the complete list. We publish it because you are entitled to know who touches your data, and because publishing it forces us to keep it accurate.
| Sub-processor | Purpose | Data it touches |
|---|---|---|
| Microsoft 365 | Email, documents, identity | All categories |
| Recruiterflow | Applicant tracking | Candidate records and applications |
| Zoho CRM | Client relationship management | Client and prospect business contacts |
| Cloudflare | Website hosting and bot protection | Form submissions in transit; IP addresses |
| ZeptoMail | Transactional email | Names and contact details in notification emails |
| Beehiiv | Newsletter distribution | Subscriber email and preferences |
| Google Analytics | Aggregated website analytics | Truncated IP, device, pages visited — after consent only |
This is the complete list as of the date at the top of this page.
We engage no offshore contractors, no outsourced delivery partners and no BPO providers. Everyone who touches your data is a Recruise employee in India.
07 If something goes wrong
Our people report a suspected incident internally immediately — not after they have confirmed it, and not at the end of the day. From there:
- Within 24 hours of verification
- We notify you, or sooner where your contract requires it. You get what happened, which of your data was involved, the cause where we know it, what we have done to contain it, and a named contact.
- Within 7 days
- A written incident report.
- Within 30 days
- A post-incident review: root cause, which control should have caught it, what changes, and who owns the change.
We also meet the statutory reporting obligations that apply to us in India, including CERT-In timelines, and we will not name you or your customers in any regulatory or public notice without your prior written consent.
A breach at one of our sub-processors that affects your data is treated as our incident. We will not wait for them to notify you on our behalf.
08 Regulatory position
- India
- The Digital Personal Data Protection Act 2023 and the DPDP Rules 2025; the Information Technology Act 2000 and the CERT-In directions.
- EU & UK
- The GDPR and UK GDPR where we process data of individuals in those regions. Transfers rely on adequacy decisions where they exist, otherwise Standard Contractual Clauses with the UK Addendum.
- United States
- CCPA/CPRA and comparable state laws. We do not sell or share personal information as those statutes define it.
Our Privacy Policy sets out lawful bases, data-subject rights and cross-border transfers in full. Our Candidate Data Policy covers retention and the operational detail. Our Cookie Policy lists every cookie we set.
We are not in scope for PCI DSS — we do not process payment card data. We are not a HIPAA covered entity or business associate.
09 If you need to assess us
Send your questionnaire to privacy@recruiseglobal.com and we will return it completed, in your own format, within five working days. We do not need you to chase us.
Available on request:
- Our completed control questionnaire, covering the domains ISO 27001 and SOC 2 assess
- Our policy set — access control, data classification and retention, incident response, business continuity, vulnerability management, change control, third-party risk, privacy by design
- Published certifications for our core platforms
- Configuration evidence, released to a named assessor under NDA
Three things from you make this faster, and reduce risk on both sides: tell us your data classification at the start; agree the transfer channel during onboarding rather than mid-mandate; and give us one named security contact. We will do the same.
10 Reporting a vulnerability
If you have found a security issue in our website or services, we want to hear about it.
Security contact
Report a vulnerability, or ask a security question
Email: privacy@recruiseglobal.com
Acknowledgement: within 2 business days
Machine-readable: /.well-known/security.txt
We will not take legal action against researchers who report in good faith, give us reasonable time to fix the issue, and do not access, modify, or exfiltrate data belonging to anyone else. Please do not run automated scanning that degrades service for other users, and please do not publish before we have had a chance to remediate.
The same address handles data protection matters, data-principal requests and privacy grievances — see our Privacy Policy for the full process and response times.