Compliance,
not theatre.
Screeq holds sensitive data — applicants, employees, compensation, EEO. Here's exactly what we do to protect it. Anything aspirational is labelled as such. UK customer data is hosted in AWS eu-west-2 (London) by default.
14-day free trial · No credit card · Cancel anytime
Defence in depth. Configured by default.
Encryption at rest and in transit
AES-256 at rest via our cloud provider's managed encryption. TLS 1.3 with strict HSTS for all client and inter-service traffic.
Row-level security in the database
Every tenant-scoped table enforces row-level security at the Postgres layer — not just in the UI. A misconfigured client query cannot leak across tenants.
SSO & MFA
Google OAuth on every plan today. SAML 2.0 SSO (Okta, Azure AD / Entra ID, OneLogin) available as an Enterprise add-on on request. Microsoft OAuth on the roadmap. MFA is opt-in per user today; policy-level enforcement is on the roadmap.
Audit trails on sensitive actions
Sensitive staff actions (candidate views, stage changes, exports, role assignments, settings changes) are logged with actor, timestamp, and target. Full-coverage audit across every endpoint is on the roadmap.
GDPR-aligned by design
Candidate data export and erasure built into the product, configurable retention windows per data type, EEO data segregated from hiring decisions.
Accessibility (WCAG 2.2)
WCAG 2.2 Level AA compliance is actively being implemented across the platform. A current accessibility audit report is available on request via coffee@screeq.com.
Backups via managed Postgres
Continuous backups with point-in-time recovery managed by our cloud database provider. Full backup-and-restore documentation available under NDA.
Responsible disclosure
Security reports go to our security inbox (use the form below or the contact link in the footer, subject 'Security disclosure'). Acknowledged within 24 hours, triaged within 72.
Cloud infrastructure
UK customer data is stored in AWS eu-west-2 (London) by default. No UK personal data is transferred outside the UK or EEA without Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum. Regional data-locality confirmation is available in writing on request.
SOC 2 Type II
In assessment. Screeq's control environment is mapped to the AICPA Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity and Privacy) with continuous evidence capture across the 13 scheduled compliance crons. The Type II observation window opens Q4 2026. Customers under NDA can request the current readiness letter and SoC mapping today.
GDPR & data rights
Candidate erasure and export workflows live in the product today. Configurable retention windows let you align candidate data lifecycle to your obligations. See our Privacy Policy.
Dig into the specifics.
Cross-references for legal, audit, and IT teams.
What we collect, why, and your rights as a data subject.
Standard DPA and SCCs ready for signature.
Master agreement, SLAs, and acceptable use.
Live uptime, incident history, and subscribe to updates.
Tokens, scopes, signed payloads — how integrations stay safe.
Request our SOC 2 evidence pack, pen-test summary, or DPA.
Security FAQs.
Can't find what you're looking for? Email us at .
Found a vulnerability?
Send the details via the form (preferred) or email . We acknowledge within 24 hours and triage within 72. Please don't publish details until we've shipped a fix.