Recruitment data deserves care at every layer.
Everything on this page is built and running today. Anything we would commit to in writing lives in your agreement — not in a badge on a marketing site.
Access starts narrow.
Customer boundaries, private files, and protected credentials form the base of the service.
Tenant-scoped access
Authorisation checks bind customer data to its organisation. Roles and current membership control what each user can view or change.
Private documents
Candidate, client, and protected team files are kept outside the public website and downloads pass through authenticated, scoped checks.
Protected credentials
Passwords and recovery codes are hashed. Selected high-risk fields, provider credentials, and integration tokens use application-level encryption.
Where your data actually sits.
The hosting, the encryption, the sign-ins, and what happens when a candidate asks to be forgotten.
Nothing is exposed by default
Placr runs on managed cloud infrastructure. The application and the database have no public address of their own — every request arrives through one front door we control, and there is nothing else on the internet to knock on. We name the provider, regions and architecture during security review rather than on a public page.
Encrypted on the wire and on disk
Traffic to and from Placr is HTTPS. Files and database contents are encrypted where they sit, and the most sensitive fields — CVs, contact details, credentials, integration tokens — carry a second layer of encryption whose keys belong to the application, not to the hosting provider.
Sessions expire, and so do links
Recruiter sign-ins time out rather than lasting indefinitely. The magic links you send candidates and clients are single-use, short-lived, and scoped to the one record they were issued for. Repeated failed sign-ins lock the account, and two-factor authentication is available when you want it.
You can take data out, or wipe it
Export a candidate's record whenever you need to. When someone asks to be forgotten, anonymising strips their name, contact details, CV, work history and files — and cannot be undone. Audit trails and anything under legal hold are held back, because those are often the records you are required to keep.
Untrusted documents stay contained.
The public application flow separates hostile-file inspection from the trusted recruitment application.
Abuse controls
Anonymous CV uploads are protected by bot verification, IP rate limits, file-size limits, and capacity controls before processing begins.
Isolated inspection
Public CVs enter private quarantine and are checked by a dedicated, least-privilege worker with no general application or task-queue credentials.
Bounded document handling
PDF and DOCX structure, active content, archive expansion, file integrity, and malicious content are checked before bounded text reaches the AI-assisted parser.
Candidate-controlled release
A staged CV stays hidden from the recruiter until the candidate reviews and confirms. Unconfirmed uploads expire after 24 hours and are purged automatically.
Controls people can use.
Security claims should be specific, verifiable, and connected to real product behaviour.
Human review of AI output
Extraction, matching, and generated content assist people. Customers are required to verify outputs and not use them as the sole basis for significant decisions.
Data-subject workflows
Candidate export, correction, withdrawal, retention, and anonymisation workflows support customers responding to privacy requests.
Security and activity records
Important account, access, privacy, and recruitment actions create scoped records that support investigation and accountability.
No badges we haven't earned
You will not find a SOC 2 or ISO 27001 logo here, because we do not hold those certifications yet. We would rather tell you that than let a graphic imply otherwise. The same goes for penetration-test claims and uptime guarantees.
Need to assess Placr?
Send us your security questionnaire, or ask for the architecture details, data flows and contractual terms that apply to your workspace.