Trust Centre
What this page covers
A scan-friendly view of the controls legal, security, IT, and data-protection teams usually ask about before approving RecruiterDocs for live Bullhorn contract workflows.
Procurement pack
For security or legal review, request the current procurement pack at security@recruiterdocs.com. Include your deployment model, preferred identity provider, signing provider, and whether optional AI-assisted features are in scope.
- Data Processing Agreement (DPA) and deployment-specific sub-processor list.
- Security-control summary covering authentication, access control, encryption, storage, webhooks, and production validation.
- Retention and erasure summary for placement snapshots, contract metadata, signing evidence, and audit logs.
- Optional AI-processing note that documents feature scope, provider use, human-review expectations, and non-decisioning boundaries.
- Accessibility statement and any open exceptions from the current product review.
Data protection and privacy
RecruiterDocs acts as a data controller for website, commercial, and account-contact data, and as a processor for customer recruitment data uploaded, synced, generated, approved, or signed through the service.
- Customer recruitment data can include candidate, contractor, recruiter, approver, client-contact, placement, contract, and signing-evidence data.
- Sub-processors vary by deployment and enabled features. Typical categories include hosting, object storage, email delivery, document conversion or preview, e-signature, ATS/CRM integration, monitoring, and optional AI providers.
- International transfers use appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, or UK International Data Transfer Agreements where required.
- Right-to-erasure handling can scrub personal data from placement snapshots and contract metadata while preserving non-personal audit context needed for legal continuity.
AI use boundaries
RecruiterDocs AI-assisted features are optional deployment features. They are intended to help with template-field suggestions, contract quality review, and drafting support. They are not intended to rank candidates, screen candidates, recommend hiring decisions, or make automated employment decisions.
- AI outputs require human review before use in a contract workflow.
- AI features should be disabled unless the customer has approved the relevant processor, transfer, retention, and acceptable-use terms.
- Where recruitment data is sent to an AI provider, the customer remains responsible for lawful-basis and transparency obligations for the underlying candidate or contractor data.
Security and access
- SAML 2.0 SSO can be configured for enterprise workspaces and required for workspace access. Workspace MFA can harden password-based users where SSO is not required.
- Role-based access controls restrict admin, reporting, settings, contract, approval, and document-artifact surfaces.
- API endpoints require bearer API tokens, DocuSign Connect requests require HMAC verification, and unknown signature-provider webhook receivers fail closed.
- Production validation blocks unsafe defaults such as debug mode, weak secret keys, disabled secure cookies, SQLite, sandbox DocuSign URLs, unsigned Bullhorn embed mode, and unacknowledged local document storage.
Signing evidence
Native signing and third-party signing integrations should be reviewed as evidence workflows, not just document-delivery workflows.
- Native signing records consent, timestamps, OTP or email-verification events, signer identity data, IP address, browser or device details, document hashes, and final signed-document evidence where applicable.
- DocuSign integrations use provider lifecycle events and signed-document artifacts when DocuSign is the configured signing provider.
- External approver and signer pages disclose that audit and security evidence may be recorded for the workflow.
Accessibility
RecruiterDocs targets practical accessibility for high-traffic public, approval, signing, and authenticated contract workflows. Review evidence can include keyboard navigation checks, landmark and label coverage, target-size checks, and known exceptions.
If your procurement process requires a formal WCAG 2.1 or WCAG 2.2 AA statement, request the current accessibility review status at security@recruiterdocs.com.
Review contacts
- Security and procurement: security@recruiterdocs.com
- Privacy and DPA: privacy@recruiterdocs.com
- General product questions: hello@recruiterdocs.com