Skip to content
placr
Security, stated plainly

Recruitment data deserves care at every layer.

Everything on this page is built and running today. Anything we would commit to in writing lives in your agreement — not in a badge on a marketing site.

Core controls

Access starts narrow.

Customer boundaries, private files, and protected credentials form the base of the service.

Tenant-scoped access

Authorisation checks bind customer data to its organisation. Roles and current membership control what each user can view or change.

Private documents

Candidate, client, and protected team files are kept outside the public website and downloads pass through authenticated, scoped checks.

Protected credentials

Passwords and recovery codes are hashed. Selected high-risk fields, provider credentials, and integration tokens use application-level encryption.

Platform

Where your data actually sits.

The hosting, the encryption, the sign-ins, and what happens when a candidate asks to be forgotten.

Nothing is exposed by default

Placr runs on managed cloud infrastructure. The application and the database have no public address of their own — every request arrives through one front door we control, and there is nothing else on the internet to knock on. We name the provider, regions and architecture during security review rather than on a public page.

Encrypted on the wire and on disk

Traffic to and from Placr is HTTPS. Files and database contents are encrypted where they sit, and the most sensitive fields — CVs, contact details, credentials, integration tokens — carry a second layer of encryption whose keys belong to the application, not to the hosting provider.

Sessions expire, and so do links

Recruiter sign-ins time out rather than lasting indefinitely. The magic links you send candidates and clients are single-use, short-lived, and scoped to the one record they were issued for. Repeated failed sign-ins lock the account, and two-factor authentication is available when you want it.

You can take data out, or wipe it

Export a candidate's record whenever you need to. When someone asks to be forgotten, anonymising strips their name, contact details, CV, work history and files — and cannot be undone. Audit trails and anything under legal hold are held back, because those are often the records you are required to keep.

Public CV uploads

Untrusted documents stay contained.

The public application flow separates hostile-file inspection from the trusted recruitment application.

Abuse controls

Anonymous CV uploads are protected by bot verification, IP rate limits, file-size limits, and capacity controls before processing begins.

Isolated inspection

Public CVs enter private quarantine and are checked by a dedicated, least-privilege worker with no general application or task-queue credentials.

Bounded document handling

PDF and DOCX structure, active content, archive expansion, file integrity, and malicious content are checked before bounded text reaches the AI-assisted parser.

Candidate-controlled release

A staged CV stays hidden from the recruiter until the candidate reviews and confirms. Unconfirmed uploads expire after 24 hours and are purged automatically.

Privacy and assurance

Controls people can use.

Security claims should be specific, verifiable, and connected to real product behaviour.

Human review of AI output

Extraction, matching, and generated content assist people. Customers are required to verify outputs and not use them as the sole basis for significant decisions.

Data-subject workflows

Candidate export, correction, withdrawal, retention, and anonymisation workflows support customers responding to privacy requests.

Security and activity records

Important account, access, privacy, and recruitment actions create scoped records that support investigation and accountability.

No badges we haven't earned

You will not find a SOC 2 or ISO 27001 logo here, because we do not hold those certifications yet. We would rather tell you that than let a graphic imply otherwise. The same goes for penetration-test claims and uptime guarantees.

Need to assess Placr?

Send us your security questionnaire, or ask for the architecture details, data flows and contractual terms that apply to your workspace.

Ready to put people first?

See how Placr gives your recruiters, candidates, and clients the experience they deserve.