Security

Enterprise-grade security for hiring and candidate data.

How Gigin protects your candidate data, your team's access, and your hiring workflows — from infrastructure to incident response.

Infrastructure

Infrastructure and hosting.

Infrastructure elementDetails
Cloud provider Amazon Web Services (AWS)
Primary region US-East (Virginia) — standard for US customers
US data residency Available for Enterprise plan customers. Candidate data processed and stored in US-region AWS infrastructure exclusively. Confirmed in DPA.
Redundancy Multi-availability-zone deployment — service continues if a single AWS zone experiences an outage
CDN CloudFront (AWS CDN) for static assets and career page delivery
Database Managed AWS RDS — encrypted, with automated backups at configurable intervals
Environment separation Production, staging, and development environments are fully isolated — no production data in non-production environments

SOC 2

SOC 2 status.

SOC 2 readiness programme in progress. Security controls documentation aligned to SOC 2 Trust Services Criteria is available to enterprise customers under NDA for procurement review.

Contact sales@gigin.ai with subject: Security Documentation Request.

Data protection

Data protection controls.

ControlSpecification
Encryption in transit All data transmitted between clients, candidates, and Gigin's infrastructure uses TLS 1.2 or higher. HTTPS enforced on all endpoints.
Encryption at rest Candidate data stored in Gigin's database is encrypted at rest using AES-256. Database encryption managed via AWS RDS encryption.
Key management Encryption keys managed via AWS KMS. Keys are rotated on a scheduled basis. Access to key management is restricted to a defined set of authorised personnel.
Backup encryption Database backups are encrypted using the same AES-256 standard as production data. Backups are stored in the same AWS region as the primary database.
Data retention Configurable retention policies per customer account — aligned to your organisation's requirements and applicable data protection law. Default: 24 months from last candidate engagement. Configurable to shorter periods.
Data deletion On contract termination: 30-day data export window, then full deletion from Gigin's production and backup infrastructure. Deletion certificate available on request.

Access management

Access management.

ControlDetails
Role-based access control Recruiter, Hiring Manager, Head of TA, Administrator — each role has a defined permission set. Administrators configure which team members have which role.
Single sign-on (SSO) SAML 2.0 SSO available for Enterprise plan customers via Okta, Azure AD, or any SAML-compliant identity provider. Users authenticate via your corporate IdP — no separate Gigin password required.
Multi-factor authentication (MFA) TOTP-based MFA available for all accounts. Required for Administrator accounts. Enforced at the account level for organisations that enable it.
Audit logs All user actions logged with timestamp, user ID, action type, and affected record. Audit logs are immutable — they cannot be edited or deleted by users. Exportable for compliance review.
Session management Session timeout after a configurable period of inactivity. Sessions invalidated on password change or SSO logout.
Privileged access Gigin staff access to production data is restricted to a defined set of authorised personnel. All staff access to production is logged and auditable.

AI and Human Decision-Making

AI governance and decision transparency.

Governance elementHow Gigin handles it
Gia does not make hiring decisions Gia's assessment output — scores, notes, shortlist recommendations — is always a starting point for recruiter review. No candidate is advanced, declined, or offered a position without a human review step.
Assessment criteria are customer-configured The criteria Gia uses to assess candidates are configured and owned by the customer team — not by Gigin. Gigin does not apply a proprietary scoring model without customer configuration.
Audit trail for every assessment Every Gia assessment call is recorded and transcribed. Every scoring decision is logged. Every shortlist recommendation includes Gia's reasoning. All data is available for recruiter review and audit.
EEOC-aligned criteria design Gia's assessment questions and scoring criteria are configured from job-related requirements. Protected characteristics are not assessment criteria. Gigin's customer success team reviews assessment configurations during onboarding for obvious EEOC compliance issues.
Override capability Recruiters can override any Gia recommendation at any point — advancing candidates Gia screened out, declining candidates Gia ranked highly. All overrides are logged.
Bias monitoring Gigin monitors assessment outcome distributions for patterns that may indicate unintended bias in the configured criteria. Anomalies are flagged to the customer success team for review.

Candidate data rights

Candidate data rights.

RightHow it is handled
Right of access Candidate can request a copy of the data Gigin holds about them. Requests processed within the timeframe required by applicable law (e.g. 30 days under CCPA for California residents).
Right to deletion Candidate can request deletion of their data from Gigin's systems. Deletion executed within the timeframe required by applicable law. Deletion from backups is executed at the next scheduled backup rotation.
Right to opt out of contact Candidate can opt out of all Gia outreach at any time via any message Gia sends — reply 'stop,' 'unsubscribe,' or equivalent. Opt-out is immediate and automatic. Contact your Gigin customer success manager for the candidate data rights handling documentation.

Sub-processors

Sub-processors.

Gigin uses third-party sub-processors in the delivery of its services. A current sub-processor list is maintained and available to customers. The sub-processor list is included in the Data Processing Agreement (DPA) addendum.

Primary sub-processors (indicative):

  • Amazon Web Services — infrastructure
  • Twilio — voice and SMS delivery
  • SendGrid — email delivery
  • Stripe — payment processing (does not touch candidate data)

Full list in DPA addendum.

To request the DPA and sub-processor addendum, email sales@gigin.ai with subject: DPA Request. We reply within one business day.

Incident response

Incident response.

ElementDetails
Detection Automated monitoring and alerting on infrastructure anomalies, unusual access patterns, and error rate spikes. 24/7 monitoring.
Classification Security incidents are classified by severity — Critical, High, Medium, Low — with defined response timelines per level.
Customer notification In the event of a security incident affecting customer or candidate data, Gigin notifies affected customers within the timeframe required by applicable law and our contractual commitments. Enterprise plan customers have notification timelines specified in their DPA.
Post-incident review Every Critical or High severity incident triggers a post-incident review within 5 business days. A written post-incident report is available to affected enterprise customers.

Documentation

Request security documentation.

DocumentRequest toResponse time
Data Processing Agreement (DPA) and sub-processor addendum sales@gigin.ai — subject: DPA Request 1 business day
SOC 2 report (when certified) or interim controls documentation sales@gigin.ai — subject: SOC 2 Report Request 1 business day
Security questionnaire responses (SIG Lite or custom) sales@gigin.ai — subject: Security Questionnaire 3–5 business days
Penetration test summary (on request) sales@gigin.ai — subject: Pen Test Summary Available under mutual NDA
Business Continuity and Disaster Recovery (BCDR) documentation sales@gigin.ai — subject: BCDR Documentation 3–5 business days

Let's talk

Talk to our team about enterprise security.

We'll share our current security posture, controls documentation, and answer your security questionnaire — under NDA where required.