Security & Governance

Candidate data is the most sensitive thing your firm holds.

A search firm's platform contains employment histories, salary expectations, confidential client mandates and the fact that a named executive is quietly looking. RayCruit is built so that each of those can be protected specifically, rather than behind a single blanket permission.

Permission groups
Permission group editor: per-resource read, create, update, delete and special rights across dashboard, candidates, mandates, customers, matching, exports and settings.

Tenant isolation

Each firm operates in its own tenant with its own subdomain, branding and white-labelled login. Data does not cross tenant boundaries.

  • Dedicated tenant per firm
  • Own subdomain and branded login
  • Tenant-scoped document storage
  • Portals isolated from the recruiter workspace

Access control

Access is controlled by role. RBAC (Role-Based Access Control) means you decide who may see and edit candidate data, customer information or commercial terms — so a shared talent pool and a confidential search can exist in the same tenant without either leaking.

  • Role-based permissions per record type
  • Special permissions for sensitive operations
  • Explicit document download rights
  • Per-mandate access lists for confidential searches

Authentication

Enterprise sign-in that fits an existing identity stack rather than adding another credential to manage.

  • OIDC single sign-on
  • Automatic user provisioning
  • Two-factor authentication enforceable tenant-wide
  • Passwordless portal access by secure link

Auditability

Two separate trails, because delivery review and security audit are different questions asked by different people.

  • Business activity timeline per customer, mandate and candidate
  • Separate append-only security log
  • AI calls logged with provider, model and prompt version
  • Document access and download recorded

Role model

Six roles that match how search firms divide work.

Generic admin-or-user permissions force firms to over-grant. These roles reflect the actual division of labour in a placement team, and permission groups refine them further.

Owner

Full control of the tenant, including commercial configuration and role assignment.

Admin

Platform administration, permission groups, branding, portals and integration configuration.

Recruiter

Full delivery work: mandates, candidates, evaluations, submissions and client communication.

Sourcer

Builds and enriches candidate records without access to client commercials or mandate internals.

Reviewer

Inspects evaluations and shortlists for quality without altering the underlying delivery work.

Read-only

Visibility for stakeholders who need to see progress but must not change anything.

AI processing

What happens to data that reaches an AI provider.

AI processing is confined to defined actions with defined inputs. Which provider handles which action is an operational setting, and every call is recorded.

01

Defined actions only

AI runs on specific actions — CV extraction, job ad extraction, named analyses — rather than as an open-ended assistant with access to everything.

02

Configurable providers

The platform supports OpenAI, Anthropic, Google and Mistral, and routing can be changed per action without a redeploy. The managed service currently runs on Mistral AI in Europe.

03

Structure check

Responses are checked against a fixed structure before being accepted, so malformed or unexpected output never reaches a recruiter.

04

Full call logging

Provider, model, prompt version, input and output are recorded, and can be streamed live to administrators.

05

Human review required

AI output is decision-support material. A person stands between generation and anything that reaches a client.

06

No silent overwrite

AI fills blanks and proposes changes; it does not overwrite human-authored content.

Auditability

Two separate trails, because delivery review and security audit are different questions asked by different people.

  • Business activity timeline per customer, mandate and candidate
  • Separate append-only security log
  • AI calls logged with provider, model and prompt version
  • Document access and download recorded
Audit log
Audit log listing timestamped events with action, resource and acting user, including sign-ins, uploads and notification dispatches.

Data handling

Practical controls around candidate and client data.

Consent recorded explicitly

Candidate consent is captured through the Candidate Portal as a deliberate action, with the legal basis documented.

Signed document delivery

Candidate documents are tenant-scoped and delivered through signed download links rather than open URLs.

Anonymisation as a feature

Anonymised CVs are generated systematically rather than edited by hand, which removes the most common source of accidental disclosure.

Retention under customer control

Retention follows the customer agreement and account configuration, and deletion requests are supported.

Data-processing transparency

The categories of data processed, the purposes and the provider types involved are documented in the privacy information.

Integration access is scoped

The read-only integration API uses scoped API keys and OAuth rather than shared credentials.

Contractual matters — the data-processing agreement, sub-processor list, hosting region and retention periods for your tenant — are handled as part of the customer agreement. Ask for them during the demo and we will provide the current documentation.

Bring your security questionnaire.

Procurement and data-protection review are easier when the answers are specific. We are happy to go through yours directly.