RippleHire Trust Center

Welcome to RippleHire’s
Trust Center

Built for enterprises. Trusted by the best.
Security, compliance, privacy, and responsible AI — all in one place. Explore how we protect your data, empower your hiring teams, and build trust at every step of the journey.


Security at Every Layer

We embed security into our DNA — from infrastructure to endpoints, from dev lifecycle to data storage.

Infrastructure Security

We host RippleHire on industry-leading cloud providers, Google Cloud Platform (GCP) and Amazon Web Services (AWS). All data centers undergo rigorous testing for availability and business continuity.

  • GCP Web Application Firewall (WAF) protection
  • SSL-encrypted data transfer
  • IP-restricted DB access with daily backups
  • Encrypted S3 file storage

Network Security

  • Strict firewall and VPC policies
  • SSH access only from authorized IPs
  • Full session logging and audit trails
  • Mandatory multi-factor authentication for production systems

Application Security

  • Static Application Security Testing (SAST) for all code
  • Secure SDLC with OWASP guidelines
  • Continuous vulnerability scans and patching
  • Web app protection via GCP Cloud Armor (WAF)

Product Security

  • End-to-end encryption (AES-256 at rest, TLS 1.2 in transit)
  • Role-Based Access Control (RBAC)
  • MFA for non-SSO users
  • Comprehensive audit logging
  • SAML 2.0-based SSO integration

Endpoint Security

  • Full disk encryption across all endpoints
  • DLP policies for data sharing prevention
  • Mobile Device Management via Google Workspace
  • Secure configurations, frequent patches, and lockdown protocols

Data Security & Governance

  • Real-time data access monitoring
  • Consent management built into the product
  • Automated daily + weekly backups (GCP + AWS)
  • Configurable data retention & erasure controls
  • Full compliance with customer data subject request processes

Compliance Certifications

ISO 27001:2013

Certified since 2016 | Audited annually by BSI

  • Last revision: March 11, 2022
  • Valid through: March 6, 2025

SOC 2 Type II

  • Latest Certification: March 2024
  • Audit Period: Jan 2023 – Dec 2023

GDPR Compliant

Certified since 2016 | Audited annually by BSI

  • Since May 2018
  • Audited annually via internal assessment

Privacy First. Always.

Our Privacy Principles

  • Privacy by Design: Integrated from day one
  • Global Compliance: GDPR, CCPA, and beyond
  • Transparency: Clear policies, informed usage

Data Processing Addendum

Our DPA outlines how we protect your personal data. Available upon request.

Data Transfers

We perform Transfer Impact Assessments (TIA) and support Standard Contractual Clauses (SCCs) to ensure secure international data movement.

Data Breach Response

24x7 incident detection and response

Root cause analysis + mitigation protocols

Customer notification aligned with global privacy laws

Employee Privacy Training

All RippleHire team members undergo onboarding and annual privacy/security training, audited under ISO 27001 standards.

Subprocessors

We partner with vetted service providers who meet our high standards.

Current Subprocessors
Logo 1
Logo 2
Logo 3
Logo 4
Logo 5
Logo 5
Logo 1
Logo 2
Logo 3
Logo 4
Logo 5
Logo 5
Logo 1
Logo 2
Logo 3
Logo 4
Logo 5
Logo 5

We ensure they uphold confidentiality, data protection, and compliance obligations (including GDPR).

Responsible AI at RippleHire

We don’t just build AI. We build Responsible AI that enhances hiring decisions, never replaces them.

Principles We Follow

Fairness & Inclusion

Our AI avoids using sensitive attributes like gender, ethnicity, or age, ensuring an unbiased recruitment experience.

Transparency

Every AI recommendation includes clear, explainable logic behind candidate-job matches.

Privacy & Security

All AI training data is encrypted, anonymized, and handled per global regulations (GDPR, CCPA).

Human-Centered Decision Making

AI works as a co-pilot, not an autopilot. You’re always in control.

Continuous Improvement

We conduct periodic audits of AI systems, incorporating user feedback and industry research.

Collaborative Accountability

We work closely with AI ethics researchers, regulatory bodies, and our internal Information Security team to stay ahead of evolving standards.

California Consumer Privacy Act (CCPA)

If you’re a California resident, you have the right to:

Access personal data we collect

Request deletion of your data

Know how and why we use your data