What should I ask an ATS vendor about data security?
Ask where candidate data is stored, who inside the vendor can access it, which subprocessors touch it, how access is authenticated and logged, what the breach notification process is, and how data is returned or deleted at contract end. Request written answers and current audit documentation rather than assurances given on a call.
Which questions matter most?
Start with location and residency: which country or region hosts candidate records, whether that can be specified, and whether backups sit elsewhere. Then access: which vendor staff can view customer data, under what controls, and whether that access is logged and reviewable. Then subprocessors: the parsing engine, email delivery service, video hosting, analytics and any AI provider are often separate companies handling your candidates' information, and you should have the current list in writing. Then identity: whether single sign-on is available at your tier, whether multi-factor authentication can be enforced, and how permissions are structured. Finally incident handling: notification timelines, who is contacted, and what support you receive. These questions are answerable by any serious vendor, and hesitation on any of them is itself informative.
What documentation should you actually receive?
Ask for a current independent audit report or certification summary, a data processing agreement, a subprocessor list, an architecture or security overview, and the vendor's policies on retention, deletion and backup. Check dates on everything, because certifications lapse and reports cover a specific period. Read the data processing agreement rather than filing it, since it defines the legal relationship: your organisation is normally the controller deciding why candidate data is processed, and the vendor is the processor acting on your instructions. That distinction determines who is accountable for candidate rights requests, and it should match what the contract says. If the vendor's security page makes claims that the documentation does not support, resolve the difference before signing rather than assuming the stronger version applies.
Who inside your organisation should review this?
IT or security reviews the technical controls, legal or privacy reviews the data agreement and transfer arrangements, and recruiting reviews the practical implications: whether permission levels match how your team works, whether interview feedback and salary details can be restricted, and whether the retention settings match your policy. Run this review during evaluation rather than after selecting a vendor, because security review is the most common reason a decision stalls late. Send the questionnaire out at the same time as your demo invitations. Where you have no internal security function, ask the vendor to walk a technically literate colleague through their overview and treat unanswered questions as open items on the scoring sheet alongside the functional requirements.
What security questions do buyers usually forget?
Four recur. First, candidate rights: how a deletion or access request is executed in the product, and whether a recruiter can do it or it needs a support ticket. Second, exit: what format data is returned in, how long you have to retrieve it, and when the vendor deletes their copies including backups. Third, email and domain: how the system sends candidate email, since deliverability and domain authentication involve your DNS and your security team. Fourth, AI processing: whether any screening or matching feature sends candidate data to a third-party model provider, where that happens, and whether it can be turned off. That last one has become the most consequential omission as AI features spread through recruiting tools, and it deserves a written answer.
Related glossary terms
Related roles to hire
Choosing your recruiting stack
Next step
Frequently asked questions
Is a security certification enough on its own?
Who owns candidate data in an ATS?
Do we need single sign-on for a small team?
What should the breach notification clause say?
See how this works in a real applicant tracking system
Pitch N Hire is an applicant tracking system built for recruiters and hiring teams. If this answer described something you want to run properly, the ATS is where it lives.
Free for 1 user Β· No credit card Β· Talk to a real hiring expert
See how much faster your team could hire
Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.
Prefer to talk? Book a demo Talk to sales View pricing
Free 1-user plan Β· No credit card Β· Talk to a real hiring expert