For CIOs and IT Leaders

Your security team will have questions about any ATS you buy. Here are the answers.

RippleHire is ISO 27001 certified, SOC 2 Type II certified, and GDPR compliant. Everything your procurement, legal, and IT teams need for vendor due diligence is documented and available on request.

Leadership Hiring 1

Choosing an ATS is not just an HR decision anymore. It is a security and compliance decision.

Candidate data is regulated material. Every resume, interview recording, background check, and offer letter is subject to GDPR, India's DPDP Act, the EU AI Act, and a growing list of jurisdiction-specific requirements. The ATS your organization uses processes all of it. Your security team should be as involved in this decision as your CHRO.

image (6)

What RippleHire gives CIOs and IT leaders to work with.

microchip-ai (2) 1 ISO 27001 certified since 2016, audited annually by BSI - not self-attested
SOC 2 Type II certified - latest audit period January to December 2023
AES-256 encryption at rest, TLS 1.2 in transit across all data flows
SAML 2.0 SSO and SCIM provisioning supported for enterprise identity management
Role-based access control, MFA for non-SSO users, and full session logging
No-code integration framework - connects to your HRMS, job boards, and communication tools without custom development
image (5)

IT and security teams at these types of organizations evaluate RippleHire.

Enterprises with data residency requirements for India, UAE, Saudi Arabia, or other jurisdictions

Organizations subject to the EU AI Act, GDPR, or India's DPDP Act for candidate data

IT teams managing complex HRMS integrations with SAP SuccessFactors, Workday, or Oracle

Security teams doing full vendor assessment including pen test summaries and security questionnaires

Proof numbers

ISO 27001

 certified since 2016, audited annually 

SOC 2 Type II

latest audit period January to December 2023

50+

countries where RippleHire data and compliance controls are active

See what your day looks like when the system handles the admin.

Audit reports, Data Processing Addendum, subprocessor list, and Master Subscription Agreement are available to qualified enterprise buyers. Reach out to trust@ripplehire.com or book a technical review with our security team.

FAQs

1. What security certifications does RippleHire hold?

ISO 27001:2013 certified since 2016, audited annually by BSI. SOC 2 Type II certified, latest audit period January to December 2023. GDPR compliant since 2018. Full documentation available at trust@ripplehire.com.

2. Where is candidate data hosted?

RippleHire is hosted on Google Cloud Platform and Amazon Web Services. Data residency options are configurable for jurisdictions with local storage requirements including India, UAE, and Saudi Arabia.

3. Does RippleHire support SSO and SCIM?

Yes. SAML 2.0 SSO integration is supported. SCIM provisioning is supported for automated user lifecycle management across your identity provider.

4. How does RippleHire handle the EU AI Act and AI governance requirements?

Every AI decision is logged automatically. Candidate notification of AI use is standard across all AI-assisted hiring stages. Bias monitoring and annual audit data generation support EU AI Act, NYC Local Law 144, and California ADS requirements. Human review gates are configurable and maintained across all agent-influenced decisions.

5. Can we get a security questionnaire completed or a penetration test report?

Yes. Security questionnaires, penetration test summaries, and additional technical documentation are available through the formal vendor assessment process. Contact trust@ripplehire.com to initiate.

6. Is RippleHire subject to the CLOUD Act?

RippleHire is not a US-headquartered vendor. For enterprises assessing US-headquartered ATS vendors for EU or Indian candidate data, third-country access analysis should be part of vendor due diligence.