Menu

For security and compliance

A hiring control that survives an audit.

Identity verification answers whether a real person exists. Organised infiltration passes that test, because it uses real stolen identities.

The identity check is not the control you think it is

A stolen but genuine identity passes liveness, document and database checks.

Hiring tooling is becoming an audit surface

Candidate screening is high risk under the AI Act, with obligations from 2 December 2027.

Vendors add legal risk while removing operational risk

Device agents, behavioural analytics and emotion inference create exposure under the GDPR and the AI Act that outweighs whatever they detect.

Provenance on every finding

Source, time of query and rule version are required fields.

Append only history

Events are never edited or deleted.

No prohibited practice

No emotion or deception detection, no biometric template, no behavioural inference, no device agent.

Isolation by construction

Row level security on every table, forced, with the application role holding neither table ownership nor a bypass right.

The API is public surface

Endpoints, webhooks and a deterministic sandbox are documented.

The security review pack, the data flow diagram and the list of subprocessors are available on request before any commercial conversation, because that is the order these decisions actually get made in.

Ask the hard question in writing.

Send the objection your team would raise and you get an answer in writing, not a call invitation.

Get accessWrite to us