Security

Security controls for Bullhorn contract workflows

How RecruiterDocs protects placement data, contract documents, and candidate records across the workflow.

In short

What this page covers

This page describes the controls visible in the product and codebase today, plus the areas where deployment-specific detail is available on request.

Access controlsRole-based permissions, approval tokens, and restricted admin surfaces.
Integration securityAuthenticated API tokens, webhook HMAC verification, and fail-closed endpoints.
Data protectionEncryption at rest for secrets, GDPR Article 17 erasure, and configurable retention.

Overview

RecruiterDocs is designed around role-based access, auditable contract actions, internal-only document preview, and fail-closed handling for integration endpoints. Production startup validation blocks deployment when required security settings are missing or misconfigured.

Need a DPA, sub-processor list, AI-processing note, or deployment-specific security pack? Start with the Trust Centre or email security@recruiterdocs.com.

Security highlights

1. Application access control

2. Data protection

3. Personal data and GDPR

4. Authentication and integration security

For the full integration surface — Bullhorn sync, signing, webhooks, and API tokens — see the integrations and technical overview.

5. Production hardening

6. Operational and deployment detail

Some operational controls depend on how RecruiterDocs is deployed. Hosting location, logging, backup frequency, restore procedures, and incident-handling commitments vary by deployment and are documented in the security pack available from the team.

7. Customer responsibilities

Security is a shared responsibility. To keep your data safe, we ask customers to:

8. Questions and security contact

If you have security questions, need a copy of our DPA, or want more detail about specific controls:

Security email: security@recruiterdocs.com
General support: support@recruiterdocs.com

Need this for legal or security review?

Send the controls your reviewer cares about — SSO, MFA, data retention, signing evidence, subprocessors, and deployment-specific safeguards — and we will return the relevant security pack.

Request security pack