Frequently Asked Questions
Find answers to common security and compliance questions about Talentpool
All data is securely hosted on AWS data centers in Mumbai and Singapore, with geo-redundant backups to ensure resilience and disaster recovery.
AI powers multiple hiring workflows, including resume parsing, candidate recommendations, job description generation, and profile summaries. These models adapt over time and are designed with privacy by default, removing personal details before processing.
Yes. OpenAI and Together AI are used in a controlled manner for JD generation and selective parsing/summarization. Data is minimized and not retained for provider training.
Recommendations surface the why (e.g., skills/experience/location match) so teams can prioritize candidates and validate decisions quickly.
Talentpool integrates OpenAI and Together AI in a way that eliminates biased language, ensuring fair and inclusive communication across hiring workflows. We provide audit-ready reports from sourcing through candidate joining, giving customers complete transparency to validate fairness within their own processes. Rather than enforcing a predefined framework, Talentpool gives organizatiosn the liberty to enforce their DEI policies.
Personally identifiable information and sensitive fields are excluded or masked before any LLM call. We do not allow model training on your tenant data.
Yes. TLS secures all data in transit and AWS-native encryption secures all data at rest. Encryption keys are managed under strict security policies.
Talentpool commits to an SLA-backed uptime and proactively scales infrastructure to handle seasonal hiring spikes. We optimize both at the code level and infra level to prevent bottlenecks.
Talentpool maintains geo-redundant, encrypted backups within AWS, with two backups stored in different global regions. Disaster recovery plans are tested periodically, ensuring a Recovery Time Objective (RTO) of 24 hours and a Recovery Point Objective (RPO) of 4 hours, minimizing downtime and guaranteeing resilience even if one region becomes unavailable.
Yes. Talentpool aligns with ISO 27001 practices, holds SOC 2 Type II certification, and complies with GDPR obligations. Our policies, controls, and infrastructure are regularly audited to maintain adherence to these global security and privacy standards.
Yes. AWS CloudTrail logs all API calls, user activity, and administrative actions. Logs are monitored, reviewed, and retained for audit and compliance purposes, ensuring full traceability of system access and data activity.
Talentpool supports secure erasure of candidate data. Upon contract termination or request, in line with data retention policies, all data added to Talentpool can be archived. Data anonymization may be available upon discussion.
Talentpool is hosted on Amazon Web Services (AWS) because of its secure, scalable infrastructure with industry-leading compliance certifications, resilience, and availability across multiple regions.
Talentpool enforces access management through role-based access controls (RBAC), Multi-Factor Authentication (MFA), and strict least-privilege policies, all managed via AWS Identity and Access Management (IAM). Administrative access is logged, monitored, and reviewed regularly using AWS CloudTrail, ensuring compliance with security and privacy requirements.
Customer data is logically segregated, encrypted, and stored in private AWS subnets with whitelisted IP access only. This ensures no data is shared between customers, maintaining confidentiality in a multi-tenant environment.
In the rare event of downtime, Talentpool's disaster recovery plan and redundant AWS infrastructure ensure services are restored quickly.
Talentpool supports SSO integrations (including Azure AD) that can be explored based on customer requirements. Role and access controls can be aligned with an enterprise's existing IT policies.
Talentpool does not engage with direct vendors. Where subprocessors are required (e.g., AWS for hosting, assessment providers, or HRMS integrations), they are introduced only with customer knowledge and consent. All subprocessors undergo rigorous security due diligence and operate under strict Data Processing Agreements (DPAs) with confidentiality and compliance clauses. Customers are given full visibility into vendor terms and conditions, and no integration is performed without explicit approval.
We design our web experience to align with WCAG 2.1 AA guidelines (keyboard navigation, color contrast, form labels, alt text). We're continually improving accessibility and can share our current practices on request.
We support REST APIs for real-time operations and SFTP for scheduled/master data updates (e.g., nightly syncs)
Documents are stored in Talentpool and can be downloaded anytime. Native storage in Microsoft 365 isn't enabled today.
We don't rely on Microsoft 365 for versioning/audits. Talentpool provides built-in document versioning and real-time audit logs for Candidates and Positions. For other entities, audit reports can be generated on demand.
Yes. Talentpool supports Single Sign-On (SSO) with Microsoft 365, ensuring that access and user roles are fully controlled by your organization's IT team. Talentpool administrators have zero control, all permissions, access policies, and regulations are enforced directly through your Microsoft 365 admin console. This gives your team complete authority to manage authentication and access in line with your internal security policies.
