Skip to content
    All legal policies
    TruTalent legal

    Data Trust, Security & Verification

    TruTalent's trust commitments, security baseline, shared responsibility model, assurance roadmap, and what verification results and trust signals mean.

    Version 1.0Effective 15 July 2026Last updated 15 July 2026

    This page combines the Data Trust and Security Statement with the Verification and Trust Signal Disclaimer — together they describe how TruTalent protects data and how verification results and trust signals must be interpreted.

    On this page

    Part 1 of 2

    Data Trust and Security Statement

    The commitments and controls behind how TruTalent handles data.

    Trust commitments

    TruTalent follows these commitments:

    1. Purpose limitation: candidate data is used for disclosed talent and hiring purposes.
    2. No data sale: candidate personal data is not sold to unrelated third parties.
    3. Restricted source documents: verification evidence is access-limited and minimized.
    4. Human accountability: AI supports rather than replaces accountable employment decisions.
    5. Training control: paid enterprise Customer Content is not used to train generally available foundation models without express written opt-in.
    6. Security by design: least privilege, encryption, logging, secure development, monitoring, incident response, and vendor due diligence.
    7. Rights and correction: candidates can request access, correction, deletion, and human review subject to law.
    8. Traceability: material verification and AI workflows should maintain version, source, timestamp, and reviewer records.

    Security overview

    TruTalent's baseline includes TLS in transit; encryption at rest where supported; secrets management; separate environments; role-based and privileged-access controls; MFA for administrators; logging and alerting; backups; vulnerability scanning; dependency management; code review; incident handling; vendor assessment; and workforce confidentiality.

    Shared responsibility

    Customers must configure access, remove departed users, protect exports, define retention, validate hiring criteria, manage their endpoints, and report incidents. Security questionnaires and contractual commitments should reflect implemented — not planned — controls.

    Assurance roadmap

    TruTalent should maintain a control register mapped to DPDP, ISO 27001, SOC 2, GDPR, and applicable AI-hiring requirements. Certifications must not be claimed until independently achieved.

    Part 2 of 2

    Verification and Trust Signal Disclaimer

    How verification results and trust signals must be read and used.

    Meaning of a verification result

    A verification result means that TruTalent or an approved provider applied a stated method to information available at a point in time. It does not guarantee identity, integrity, future performance, employment suitability, legal eligibility, or authenticity beyond the scope of that method.

    Trust and consistency signals

    A trust, consistency, completeness, or anomaly signal is decision-support information. It may be affected by missing data, name variations, employment practices, document quality, model limitations, or provider errors. It must not be treated as a character judgment, fraud finding, or automatic rejection criterion.

    Candidate safeguards

    Candidates may request correction, submit alternative evidence, explain discrepancies, and seek human review. Material adverse action should not be taken solely because a signal is low, absent, or inconclusive.

    Customer duty

    Employers and recruiters must evaluate job relevance, use proportionate evidence, comply with background-check and employment laws, provide required notices, and maintain human accountability.