Skima AI
Home Answer Hub Talent Rediscovery How secure is our candidate database when using a third-party rediscovery tool?

How secure is our candidate database when using a third-party rediscovery tool?

September 17, 2026
Akshata Pawar

Akshata Pawar

Senior TA Specialist

About

I’m a senior recruiter with 5 years of experience in talent acquisition, HR, and hiring technology. I write data-driven product reviews, ATS evaluations, and comparisons that help HR leaders choose tools with confidence.

Find Akshata here

Your candidate database remains secure with a reputable rediscovery vendor as long as the tool encrypts data in transit and at rest, operates under a signed Data Processing Agreement, and maintains independent security certification like SOC 2. Confirm each of these directly with any vendor instead of assuming security based on a polished sales pitch.

When evaluating a vendor's security posture, check for these specific items:

  • Encryption in Transit and at Rest: Candidate data should be encrypted both while moving between your ATS and the rediscovery tool, and while stored on the vendor's servers.
  • A Signed Data Processing Agreement: A DPA legally defines how the vendor can use your candidate data and confirms it remains outside their general model training.
  • Independent Certification: SOC 2 compliance means an outside auditor has verified the vendor's security controls, not just the vendor's own claims.
  • API-Based Access, Not Data Export: The tool should connect through your ATS's own API instead of requiring a bulk export of your candidate database to an external file.

Platforms like Skima AI meet these criteria directly. It connects through each ATS's own REST API rather than requiring data exports, encrypts candidate data in transit and at rest, operates under a signed DPA, and maintains SOC 2 and GDPR compliance. It also aligns with frameworks including the EU AI Act and NYC Local Law 144, which are relevant for agencies placing candidates across multiple states or countries.

Your agency's own retention policy still applies, regardless of vendor security. A secure tool protects data while it holds it, but your agency remains responsible for determining how long candidate data stays in the system in the first place.