# Hiring Data Security: What to Verify with Skill Society

Canonical URL: https://skillsociety.com.au/blog/posts/security-compliance-features
Markdown URL: https://skillsociety.com.au/blog/posts/security-compliance-features/markdown
Published: 2026-06-11
Updated: 2026-09-16
Author: Alberto Cubeddu
Excerpt: Review Skill Society’s published privacy and access controls, then verify hosting, retention, integrations and assurance evidence for your hiring workflow.

A hiring-data security review should establish what information is collected, who can access it, where it is processed and how it is retained or deleted. A product's security language is not a substitute for the evidence and contractual commitments your organisation needs.

This guide distinguishes Skill Society's published policy and product behaviour from matters to verify for a particular deployment. It does not claim a SOC 2 attestation, ISO 27001 certification, universal regulatory compliance or an Australia-only hosting guarantee.

## What information does the hiring workflow handle?

Skill Society's [privacy policy](https://skillsociety.com.au/privacy) describes application and account information, interview recordings, transcripts, AI evaluations, communications, usage data and information received from integrations. Which categories are processed depends on the workflow you enable.

Before a pilot, map the candidate, referee, hiring team and connected systems. Record the purpose of each field, the recipient and the retention owner. Avoid collecting information merely because a form permits it.

## Where is data processed?

The published privacy policy allows transfers and storage in Australia or other jurisdictions where service providers operate. Buyers should therefore verify the actual processing locations for their account, including voice processing, AI providers, backups, logs and connected systems. Do not infer exclusive Australian or EU residency from a general statement about local hosting.

Ask for the current subprocessor and data-flow information relevant to the service you will use. If a particular residency or transfer requirement is mandatory, include it in the vendor review and agreement before sending candidate records.

## What access controls are documented?

The [Collaborative Hiring page](https://skillsociety.com.au/solutions/collaborative-hiring) describes Administrators with account-wide responsibilities and Members assigned to specific active roles. Eligible feature permissions and the account's entitlement also affect what a person can view or operate. The page describes live access revocation and internal candidate comments.

Those controls support separation of hiring responsibilities. They do not, by themselves, establish a complete security audit trail, a separate client tenant for every agency customer, or that every feature is included in every plan.

A useful demonstration includes an authorised reviewer opening an assigned role, an unassigned user being denied access and a removed reviewer losing access. Confirm identity-provider support and authentication requirements for the actual account rather than assuming SSO or mandatory MFA is included.

## What should a security review request?

| Area | Evidence to request |
| --- | --- |
| Encryption | Current implementation scope for data in transit and at rest, including relevant providers |
| Independent assurance | Any available audit report or certificate, its scope, issuer, dates and exceptions |
| Access and activity | Permission model, available logs, exportability and log-retention periods |
| Availability and recovery | Applicable service commitments, backup arrangements and tested recovery objectives |
| Incident response | Customer contact path, notification commitments and responsibilities |
| Integration access | Authentication method, scopes, credential owner, revocation and failure handling |
| AI processing | Providers, processing purpose, retention and any training-use commitments |

Request the evidence your procurement process requires. This table is not a claim that every named document or control is currently offered. Infrastructure providers' certifications also do not certify the application as a whole.

## Retention, deletion and connected copies

The [privacy policy](https://skillsociety.com.au/privacy) describes retention for necessary purposes and legal or contractual requirements, and a route to request deletion or custom retention terms. Confirm the operational process and timing, including treatment of backups and logs, before promising a candidate immediate or complete erasure.

Map copies sent to an ATS, downloaded reports and other recipients. Deleting a record in one system does not necessarily delete every copy. Ask how a connected source is prevented from sending the same record again and which organisation handles each part of a request.

## Human review belongs in the data workflow

Candidate evidence needs both access controls and responsible interpretation. Reviewers should check original answers and recordings where appropriate, correct material transcript errors and distinguish an incomplete response from a failed requirement.

Configured qualification rules can route applications, while people retain responsibility for hiring decisions. Consistent questions alone do not demonstrate that an assessment is accurate, bias-free or legally compliant. Keep the role criteria and review responsibilities clear.

## Prepare for a review

Bring a short inventory of the data you intend to collect, required integrations, user roles, locations and retention needs. Then [book a Skill Society review](https://skillsociety.com.au/booking?utm_source=blog&utm_medium=cta&utm_campaign=security-review) to establish which requirements can be supported and what evidence is available.

Use the current policy, demonstrated configuration and agreed terms for the final decision.
