HR Software

What should I ask an ATS vendor about data security?

Ask where candidate data is stored, who inside the vendor can access it, which subprocessors touch it, how access is authenticated and logged, what the breach notification process is, and how data is returned or deleted at contract end. Request written answers and current audit documentation rather than assurances given on a call.

Which questions matter most?

Start with location and residency: which country or region hosts candidate records, whether that can be specified, and whether backups sit elsewhere. Then access: which vendor staff can view customer data, under what controls, and whether that access is logged and reviewable. Then subprocessors: the parsing engine, email delivery service, video hosting, analytics and any AI provider are often separate companies handling your candidates' information, and you should have the current list in writing. Then identity: whether single sign-on is available at your tier, whether multi-factor authentication can be enforced, and how permissions are structured. Finally incident handling: notification timelines, who is contacted, and what support you receive. These questions are answerable by any serious vendor, and hesitation on any of them is itself informative.

What documentation should you actually receive?

Ask for a current independent audit report or certification summary, a data processing agreement, a subprocessor list, an architecture or security overview, and the vendor's policies on retention, deletion and backup. Check dates on everything, because certifications lapse and reports cover a specific period. Read the data processing agreement rather than filing it, since it defines the legal relationship: your organisation is normally the controller deciding why candidate data is processed, and the vendor is the processor acting on your instructions. That distinction determines who is accountable for candidate rights requests, and it should match what the contract says. If the vendor's security page makes claims that the documentation does not support, resolve the difference before signing rather than assuming the stronger version applies.

Who inside your organisation should review this?

IT or security reviews the technical controls, legal or privacy reviews the data agreement and transfer arrangements, and recruiting reviews the practical implications: whether permission levels match how your team works, whether interview feedback and salary details can be restricted, and whether the retention settings match your policy. Run this review during evaluation rather than after selecting a vendor, because security review is the most common reason a decision stalls late. Send the questionnaire out at the same time as your demo invitations. Where you have no internal security function, ask the vendor to walk a technically literate colleague through their overview and treat unanswered questions as open items on the scoring sheet alongside [the functional requirements](/ats-features).

What security questions do buyers usually forget?

Four recur. First, candidate rights: how a deletion or access request is executed in the product, and whether a recruiter can do it or it needs a support ticket. Second, exit: what format data is returned in, how long you have to retrieve it, and when the vendor deletes their copies including backups. Third, email and domain: how the system sends candidate email, since deliverability and domain authentication involve your DNS and your security team. Fourth, AI processing: whether any screening or matching feature sends candidate data to a third-party model provider, where that happens, and whether it can be turned off. That last one has become the most consequential omission as [AI features spread through recruiting tools](/ai-recruiting-tools), and it deserves a written answer.

Want Pitch N Hire to handle this for your team?

Related glossary terms

Related roles to hire

Next step

FAQ

Frequently asked questions

Is a security certification enough on its own? +
It is a useful baseline, not a complete answer. Certifications confirm that controls were assessed against a framework during a defined period; they do not tell you where your data will sit, which subprocessors handle it, or how deletion works in the product. Read the certification alongside the data agreement and the retention settings you will actually use.
Who owns candidate data in an ATS? +
Your organisation should, and the contract should say so explicitly along with your right to export it during the term and at the end. Read any clause granting the vendor rights to use customer data for product improvement or model training, and confirm whether it applies by default and whether it can be switched off for your account.
Do we need single sign-on for a small team? +
It is not essential at very small scale, but it becomes valuable quickly because it centralises access removal when someone leaves. If single sign-on sits in a higher tier, factor that into the comparison. Where it is unavailable, insist on enforced multi-factor authentication and a documented process for revoking accounts promptly.
What should the breach notification clause say? +
It should commit the vendor to notifying you without undue delay within a defined period, describe what information you receive, and name the contact route. You need this because your own regulatory notification clock depends on their timeliness. A clause that promises notification without any timeframe leaves you exposed to their internal judgement.
Built for recruiters & hiring teams

See how much faster your team could hire

Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.

Prefer to talk? Book a demo · View pricing

Free 1-user plan · No credit card · Talk to a real hiring expert

One Hiring Infrastructure.
Zero Tool Chaos.

Demos are consultative. We respect privacy and enterprise
governance. No lock-ins.

Start free Book demo