Is my candidate data safe with a rediscovery software vendor?
With a reputable vendor, yes. Look for encryption in transit and at rest, a signed Data Processing Agreement, and independent security certifications like SOC 2 before trusting any tool with your candidate database.
Three protections matter most when evaluating a vendor's data security:
- Encryption. Candidate data should stay encrypted both while moving between systems and while stored on the vendor's servers.
- A signed DPA. A Data Processing Agreement legally defines how the vendor can use your candidate data and confirms they cannot use it for purposes outside your agreement.
- Independent certification. SOC 2 compliance means an outside auditor has verified the vendor's security controls, not just the vendor's own claims.
Software vendors like Skima AI meets all three. It encrypts candidate data in transit and at rest, operates under a signed DPA, and maintains SOC 2 and GDPR compliance. Each client also operates in a logically isolated tenant environment, meaning your candidate data never mixes with another company's data, and it is never used to train Skima AI's general models.
For AI-specific concerns, ask one more question: does candidate data ever get sent to a public AI API outside the vendor's own systems? Skima AI processes candidate resumes and personal information exclusively through its own internal models, not through public AI services like OpenAI, keeping sensitive data inside a closed environment.
Before signing up with any vendor, ask directly about their DPA terms, encryption standards, and certifications rather than assuming safety from a polished website.