VoyseBook a demo
TRUST CENTRE

Security, privacy and AI governance, in the open.

Voyse connects live to your ATS and runs an assistant on your careers site. Here is how we protect candidate data, govern the models, and stay accountable — with the full Trust Pack available once we're engaged.

CERTIFICATIONS & FRAMEWORKS

Where we are on the standards that matter.

We state status plainly, without dates. “In progress” means work that is genuinely underway — we don't pre-announce certifications we haven't begun.

AI MANAGEMENTISO/IEC 42001The management-system standard for AI.Audit underway
INFORMATION SECURITYISO/IEC 27001Information security management system.In progress
AI RISKNIST AI RMFAI risk-management framework. Alignment, not certification.Aligned
CYBER HYGIENECyber EssentialsUK baseline cyber-hygiene scheme.Certified
HOW VOYSE PROTECTS YOUR DATA

Four commitments, each documented in full.

The summaries below are the public version. Every one expands into evidence, control mappings and operating detail in the Trust Pack.

01 · SECURITY

Controls built for a managed cloud.

Logical tenant isolation on every authenticated request, least-privilege access, and secrets kept out of code — running on a serverless AWS estate defined entirely as code.

  • TLS 1.2+ in transit; encryption at rest with keys rotated every 60 days
  • SAST, secret scanning and dependency alerts gate every release
  • Independent penetration testing on an annual basis
02 · PRIVACY

Processor by design, under UK GDPR.

You stay the controller for candidate data and set the lawful basis; Voyse processes on your documented instructions under a data processing agreement, and never determines the purpose.

  • Data-subject rights supported and assisted within 30 days
  • Customer data deleted or returned within 30 days of termination
  • Transfers covered by the UK IDTA and EU SCCs, with risk assessed
03 · AI GOVERNANCE

Grounded answers, humans in control.

The assistant answers only from content you approve, cites its sources, and says so when it doesn't know. It never screens, scores, ranks or rejects candidates, and makes no hiring decisions.

  • Foundation models accessed under zero-retention API terms
  • Model and prompt changes pass a behavioural test suite before release
  • Defined escalation path to the AI-system owner (the CTO)
04 · RESILIENCE

Recoverable, monitored, accountable.

Serverless across multiple availability zones, daily snapshots exported to independent storage, and a severity-graded incident process with a clear customer-notification commitment.

  • Recovery point up to 24 hours; recovery time from 2 working hours
  • Status posted to status.voyse.io; direct notification for Level 1–2
  • Blameless post-incident review within five working days
VOYSE INTELLIGENCE · TRAINING-DATA POLICY

We do not train models on your data.

These commitments cover Voyse Intelligence, our AI assistant. Customer and candidate data is used only to serve your own tenant at inference time. It is never pooled across tenants for model training, and it is never used to train Voyse-owned models. Foundation models are accessed via provider APIs under enterprise terms that prohibit training on submitted data.

Surfaced only when relevant

Candidate and company information appears only when it is directly relevant to the question at hand — grounded in retrieved evidence, never inferred.

You decide what it can say

The assistant answers from the knowledge base you curate and the campaigns you configure. Defaults are conservative: approved content only.

Every answer is attributed

Each claim carries a structured reference to the source it came from, so any surfaced statement can be traced to its origin.

SUB-PROCESSORS

Third parties that process data.

This is the canonical, public list. Customers are notified of material changes per the data processing agreement.

Updated May 2026
Sub-processorPurposeProcessing locationSecurity page
Amazon Web ServicesCloud hosting, compute, storage, identity, email & messagingEU · Irelandaws.amazon.com/compliance
AWS Bedrock (Amazon Nova)AI inference — classification, query & memory tasksEU · Irelandaws.amazon.com/bedrock
MongoDB AtlasPrimary database & vector searchEU · Irelandmongodb.com/trust
OpenAILLM inference (final answer) & text embeddingsUnited Statesopenai.com/security
CloudinaryMedia storage & delivery (images, video)United Statescloudinary.com/trust-center
PerplexityAI research enrichment (ancillary)United Statesperplexity.ai/hub/legal

US transfers rely on the UK IDTA and, for EU data, the EU SCCs, with transfer risk assessed. Full scopes and contractual terms are available under NDA.

DATA PROTECTION

The essentials, stated plainly.

DATA RESIDENCY
EU · Ireland
Primary processing in AWS eu-west-1. UK–EU transfers covered by the EEA adequacy decision.
ROLES
You control, we process
You are the controller for candidate data; Voyse is the processor under a signed DPA.
RETENTION
Your policy, then deleted
Data retained per your configuration; deleted or returned within 30 days of termination.
INTERNATIONAL TRANSFERS
IDTA & EU SCCs
Where data leaves the UK for US inference, transfers rely on the IDTA and SCCs.
DOCUMENTATION & ACCESS

What you need to complete a review.

So you don't have to start from a blank questionnaire. Request anything below from the security team.

Available now
  • Trust Pack — the full reference, shared once we're engaged
  • CAIQ Lite & SIG Lite — pre-filled questionnaire responses
  • Data processing agreement — ready for digital signature
  • Live sub-processor list — maintained on this page
Available under NDA
  • Penetration-test summary — latest independent test letter
  • DPIA template — covering the standard Voyse processing patterns
  • Incident-response runbook — summary of the lifecycle & severities
  • BC/DR summary — business continuity & disaster recovery
REVIEWING VOYSE

One inbox for your whole security review.

Security questionnaires, NDA requests, DPA execution and vulnerability reports all go to one place. We'll route them to the right specialist, and share the full Trust Pack once we're engaged.