Security & Compliance

Enterprise-grade security,
not enterprise-grade friction.

Recubix stores biometric embeddings, interview recordings, and candidate PII. We built security at every layer — not as an afterthought.

Security & Compliance

Enterprise-grade security,
not enterprise-grade friction.

Recubix handles biometric data, interview recordings, and candidate PII — so we built security in at every layer, not as an afterthought.

SOC 2 Type II ready

Architecture designed for SOC 2 compliance. Audit trails, role-based access, and encrypted data at rest and in transit.

Biometric data protection

Face and voice embeddings are hashed and stored in isolated buckets. Raw video is deleted post-verification. Never sold or shared.

GDPR & privacy by design

Candidates can request deletion at any time. PII is isolated per organization. No cross-org data leakage, ever.

Role-based access control

Owner → Admin → Member hierarchy. Every route is org-scoped. Recruiters only see their own candidates and projects.

Full audit trail

Every action — resume upload, interview schedule, report download — is logged with actor, timestamp, and org context.

Auditable AI decisions

Every score is LLM-generated with an explicit rubric and stored verbatim. No black-box verdicts — you see the reasoning.

Also includes:AES-256 encryptionTLS 1.3 in transitIsolated org storageNo data training on your candidatesEU & US data residency

Compliance status

SOC 2 Type IIIn progress
GDPR CompliantLive
CCPA CompliantLive
AES-256 EncryptionLive
TLS 1.3 in TransitLive
FedRAMPPlanned

How biometric data flows

01

Candidate joins interview

Video stream captured locally in browser

02

Biometric check runs

Face + voice embeddings extracted on-device, sent over TLS

03

Embedding stored

Math vector saved to isolated org bucket — not raw video

04

Raw video discarded

Within 60 seconds of check completion

05

Candidate requests deletion

All vectors + metadata purged within 48 hours

Responsible AI

No black-box decisions.

Every candidate score is generated by GPT-4o using an explicit rubric grounded in the job description. The full reasoning is stored verbatim alongside the score — so you can audit any verdict, challenge any decision, and explain it to any candidate. We don't train on your candidates' data.

Rubric visible per question
Reasoning stored verbatim
No training on candidate data

Security questions?
We answer them.

Talk to our team about compliance requirements, data residency, and custom SLAs.

Talk to security team