Your hiring data is personal. Names, emails, job history, assessment results - people trust you with that, which means you're responsible for it.
We get questions about this a lot: "Where does my data live? Who can see it? Can you see it?" These are the right questions to ask any HR tool.
Here's what we actually do today, what we're building, and what we explicitly refuse to do.
What we store (and what we don't)
We collect:
Assessment results (what people answer, not how long they think)
Competency records (levels, history of changes)
Recruiting artifacts candidates submit (CVs, interview notes – not scraped profiles)
Team org structure
Exam scores (the result, not a recording of someone taking it)
We explicitly don't collect:
What you type into AI tools (no transcripts, no prompts)
Keystrokes, screenshots, idle time tracking
Email, Slack messages, or browsing history
Location or off-hours activity
Any surveillance-type data
That stuff is a red line for us. Not because we're noble – because it's creepy and unnecessary. Your hiring and assessment data tells us what we need. Everything else is noise.
How Data Is Protected
(the list is current as of today: every day we do more to ensure the platform's security)
Access controls:
Your workspace data is isolated at the database level. Your data doesn't live next to another company's data in a shared table.
Only a named set of engineers can access production. We log every access.
Your team members get role-based access: hiring manager sees hiring data, people ops sees assessments, not finance trying to peek at salaries.
If someone's password leaks, they still need a second factor to log in (we support authenticator apps and physical keys).
Encryption:
Data moving to our servers travels over HTTPS (standard encryption in transit). Not exotic, but it works.
Data at rest is encrypted. We use industry-standard encryption. Not "NSA classified data" level, but solid enough that if someone physically stole a hard drive, the data is unreadable without the key.
Backups – we test them now:
Daily encrypted backups, stored in a different geographic region.
We actually restore from backup quarterly to verify it works (not only theoretical).
If something breaks, we can restore data from the last 24 hours. We aim for 4-hour recovery time.
Incident response – we have a process:
If something goes wrong, our on-call engineer triages it, contains it, and we post-mortem it.
If we confirm a breach affecting customer personal data, we notify you within 72 hours (in line with GDPR expectations, whether you're in the EU or not).
Material post-mortems get published on our changelog so you know what happened and how we fixed it.
What We're Building
In progress – coming before we charge for Cloud:
- Full sub-processor transparency. We'll publish the list of vendors who touch your data, and you'll know exactly which ones
- AI model governance: any AI tools in the product will be configured to not train on your data or prompts
- Automated data export for recruiting data – you can export everything you submit to a job board
- Configurable data retention windows – you'll set how long recruiting data lives; for assessments, we're still building this.
We're not doing yet:
- SOC 2 certification: this is an audit that proves our controls work consistently over time. It's on our roadmap, but we're not there yet. Don't expect it Q4 2026 like we said before – we need to be further along first.
- Quarterly third-party penetration testing: we do internal security reviews, we accept responsible disclosures, but we're not running quarterly external audits. That's enterprise-scale spending.
And I want to remind you that we’d be happy to talk with investors – if that’s you, or if you know someone who might be a fit, please let us know.
- "Zero Trust architecture" as a buzzword: we have the fundamentals (MFA, access logs, isolation, role-based access). We're not going to market-speak it into something it's not.
What we actually care about:
- Code review on every change (no cowboy deploys)
- Automated tests that run on every build
- Dependency scanning for known vulnerabilities
- Incident response that's real and documented
- Telling you the truth about what we do and don't have yet :) i'm here for it
Self-Hosted vs. Cloud:
Cloud (managed by us): | Self-hosted (you control it all): |
|---|---|
- We handle the infrastructure, backups, patches, uptime. - The controls above apply. - Your data is encrypted, isolated, backed up. - If you need it, we can isolate your data to a specific geographic region (EU, US). | - You host HR Pulsar on your own infrastructure. - You own the backup strategy, the access controls, the physical security. - We don't see your data. We can't access it. We don't need to. - This is the strongest guarantee we can give: your data never leaves your server. |
If data sovereignty is a hard requirement for you, self-hosted is the right choice. If you want managed convenience with clear guardrails, Cloud works.
What you can see, and what you can control
Transparency by default: | Your rights: |
|---|---|
- Assessment scores: the person who took the assessment sees the exact same number the manager sees. - Hiring feedback: candidates get notified what happened with their application (accepted, passed screening, etc.). - AI recommendations: the system shows you it's an AI recommendation, not a final decision. A human signs off on hiring, promotion, assessment grade – not the software. | - You can request a full export of your employee record. We give it to you in structured format. - If an assessment score is wrong, there's a process to dispute it (human review, documented outcome). - You can request deletion of recruiting data. Assessment data is trickier – we're still building self-serve deletion, but it's contractually committed. |
What leaves your workspace:
Nothing identifying you or your company.
We publish anonymous industry benchmarks (e.g., "average time-to-hire in Series A tech companies"), but only if at least 20 companies are in that group. Below that threshold, no benchmark is published at all.
The Reality Check: what we can't promise
- Zero breaches. No platform has this. If somebody says it, it's lying.
- Perfection. We're a young product and we'll make mistakes.
- Enterprise-grade certifications right now. We're building toward them, but we're not there.
What we can promise: we're paranoid about access control.
Why especially startups should care:
Early-stage founders often think "we're too small to matter." Wrong. Attackers target small companies because they assume security is loose. Also: if you raise capital, investors will ask about data security. Honest answers about what you do and don't have are stronger than buzzwords.
If you have any security questions about HR Pulsar specifically, you can always contact us by email support@hrpulsar.com
Serious questions require serious answers.