Security
Security & Compliance
Last updated: 2026-04-29
Hire Stack handles candidate personal data on behalf of UK recruitment teams. Security is a first-order concern, not a checkbox. This page describes how we protect customer data.
Data residency
Customer data is processed and stored in the UK and EU. We do not transfer customer data outside the UK/EU without prior written notice. The Hire Stack web application is delivered globally via Vercel's CDN; data persistence and AI processing happen in UK/EU-located infrastructure.
Encryption
- In transit: all traffic to and from hirestack.co.uk is served over HTTPS with TLS 1.3 and HSTS preload (max-age 2 years).
- At rest: customer data is encrypted at rest using AES-256.
- Secrets: API keys and credentials are stored in encrypted secret stores, never in source control.
Access control
- All employee access to production systems requires single-sign-on with multi-factor authentication.
- Access follows least-privilege; production access is granted on a per-task basis and audited.
- Customer accounts support per-user logins with strong password requirements; SSO/SAML is on the roadmap.
Sub-processors
Hire Stack uses a small set of vetted sub-processors to deliver the service. The current list is published in our Privacy Policy. We notify customers in advance of any change.
UK GDPR
Hire Stack is operated by Hire Stack Limited under UK GDPR. We act as data processor for Customer Data; our processing obligations are codified in our Data Processing Addendum (DPA), available on request via privacy@hirestack.co.uk.
Backups and disaster recovery
Customer data is backed up daily, with backups encrypted and retained for 30 days. We test restore procedures regularly.
Incident response
Suspected security incidents trigger our incident response process. Where a personal data breach affects rights and freedoms of data subjects, we notify the ICO within 72 hours and notify affected customers without undue delay, in line with UK GDPR Articles 33 and 34.
Reporting a vulnerability
If you believe you have found a security vulnerability in Hire Stack, please email security@hirestack.co.uk. Please do not publicly disclose until we have had reasonable opportunity to investigate and remediate.
On the roadmap
- SOC 2 Type II report
- SSO/SAML for enterprise customers
- Customer-managed encryption keys (BYOK)
- Audit log export