Security and privacy
How XATZ protects the people in your pipeline.
Hiring data is some of the most personal data a company holds. This page explains, in plain language, what XATZ collects, where it goes, who can see it, how long it stays, and what the AI agents are and are not allowed to do with it.
Highlights
One tenant per organisation
Your data is scoped to your organisation at the database layer. No query, report or agent run crosses tenants.
Encrypted everywhere
TLS 1.2 or higher in transit. AES-256 at rest for databases, recordings and documents.
Least-privilege access
Roles down to individual actions. Recruiters see their pipeline, managers see their team's, admins see the organisation.
Candidates are told, and asked
Every AI interview starts with a disclosure and consent step. Zoya identifies herself as an AI on every call.
People make the decisions
Agents gather and score evidence. Advancing, rejecting and offering are done by a named person, always.
You control retention
Retention periods are set per organisation. Delete or export any candidate's data on request.
What information does XATZ process?
XATZ processes data on your behalf to run your hiring. You decide which candidates enter the system and which stages they pass through. We never collect candidate data for our own purposes.
| Category | Examples | Where it comes from | Why we process it |
|---|---|---|---|
| Your team's accounts | Names, work emails, roles, sign-in events | You | Run accounts and permissions, secure the service |
| Candidate profiles | Resumes, contact details, work history, notes, stage history | You, the sources you connect, candidates | Run your pipeline: match, screen, schedule, report |
| Outreach (Zoya) | Call audio, transcripts, outcomes, callback times, follow-up emails | Calls Zoya places on your instruction | Record what was said and agreed, follow up, write outcomes to the record |
| Interviews (Zia) | Audio recording, transcript, code submissions, scores, integrity signals | Candidate sessions | Produce the interview report your team reviews |
| Usage and technical | IP address, device and browser, feature usage, audit events | The product itself | Secure the service, investigate issues, keep the audit trail |
How does data move through XATZ?
Everything you see happens inside your own tenant. Third-party providers are used for specific steps and receive only what that step needs.
How is data secured?
- Encryption
- All traffic uses TLS 1.2 or higher. Databases, recordings and documents are encrypted at rest with AES-256. Recordings are served through short-lived, signed links, never public URLs.
- Tenant isolation
- Every record carries your organisation's identifier and every query is scoped to it at the data layer, not only in the interface. Cross-tenant access is a code-level impossibility we test for, not a policy we hope for.
- Separate environments
- Development, QA and production run as separate clusters with separate credentials and data stores. Production data is never copied into lower environments.
- Storage
- Recordings, resumes and documents live in private object storage scoped per tenant. Nothing is world-readable.
- Change control
- Changes reach production through reviewed pull requests and an automated deployment pipeline. Configuration changes that affect how candidates are treated are logged and attributed.
- Monitoring
- Service health, error rates and unusual access patterns are monitored continuously, with alerts to the engineering team.
Who can access data?
Access follows the principle of least privilege: people see the slice of the pipeline they are responsible for.
- Roles and permissions
- Administrators, recruiters and hiring managers each get permissions down to individual actions. Interviewers see only the candidates they are assessing. Permission changes take effect immediately and are logged.
- Data scoping
- A recruiter sees their own pipeline. A manager sees their recruiters' pipelines. An administrator sees the organisation. Reports respect the same scope automatically.
- Sign-in
- Team members sign in with verified work email. Sessions expire and can be revoked by an administrator. Enterprise plans can request single sign-on.
- Procyon staff
- Our staff do not access customer data in the course of normal operations. Support access happens only at your request, is limited to the issue, and is recorded in the audit log you can see.
How do the AI agents handle data?
Zoya and Zia are software that acts on your instructions inside your tenant. They have no memory across customers and cannot see another organisation's data.
- What they receive
- Only what the step needs. Zoya gets the role, the candidate's name and number, and your talking points. Zia gets the role, the interview plan and the candidate's answers. Neither receives your whole database.
- What they cannot do
- Advance, reject or make an offer. Contact a candidate who has asked not to be contacted. Act outside the autonomy level you set. Every action outside its level goes to your approval inbox instead.
- Model providers
- Language and speech providers process transcript segments, resume text and job descriptions to produce a response, and hold them only for the request. Our agreements prohibit use of your data to train their models.
- Logging
- Every agent action is written to the audit log with what triggered it, what it saw and what it did. You can replay any run.
- Disclosure
- Zoya states that she is an AI assistant at the start of every call. Zia's interview invitation and opening screen state that the interview is AI-led and recorded.
What do candidates see and agree to?
- Before the interview
- The invitation names your organisation, explains that the interview is conducted by an AI, that it is recorded, what is assessed and how long it takes. The candidate can decline and ask your team for an alternative.
- Consent
- The interview cannot start until the candidate confirms they understand and agree. Consent is timestamped and stored with the session.
- During the call
- Zoya introduces herself as an AI assistant calling on behalf of your organisation, says why she is calling, and stops if the candidate asks not to be contacted.
- Their rights
- Candidates can ask your organisation, or us, to access, correct, export or delete their data. We act on your instruction as your processor and respond within the time the applicable law requires.
How is interview integrity protected?
A score is only useful if the person interviewed is the person hired. Integrity checks protect candidates who play fair.
- Identity
- An identity check at the start of every Zia interview confirms the candidate matches the invitation.
- Environment and attention
- The session monitors for a second person, a second screen or sustained inattention. Coding tasks run in a controlled editor.
- After the session
- Recordings are analysed for signals that are hard to spot live, such as reading from another source.
- Flags, not verdicts
- Integrity signals are shown to your team as flags with evidence. Nothing is auto-rejected. You see it and decide.
How long is data kept?
You set retention per organisation. Defaults below apply until you change them.
| Data | Retention | Deletion |
|---|---|---|
| Candidate profiles and notes | While your account is active, then per your retention setting | On request, or automatically at the end of the retention period |
| Interview and call recordings | Per your retention setting (pilot default 12 months) | Deleted with the candidate, or earlier on request |
| Transcripts, scores, reports | Same as the candidate record | Deleted with the candidate |
| Audit logs | 24 months | Rolling deletion; never edited |
| Backups | Encrypted, rotated within 30 days | Deleted data ages out of backups on the same cycle |
Deletion requests are completed within 30 days and confirmed in writing. Data deleted from the live system ages out of encrypted backups on the backup cycle.
Which third parties process data?
We use a small number of providers for specific functions. Each is bound by a data processing agreement, processes data only on our instructions, and may not use it for its own purposes.
| Function | What it does for you | What it receives |
|---|---|---|
| Cloud hosting | Compute, databases, object storage for your tenant | EU data centre; SOC 2 Type II and ISO 27001 certified provider |
| Speech to text | Turning call and interview audio into text, in real time | Audio segments, transient |
| Language models | Zoya's conversation, Zia's questions and scoring, candidate ranking | Transcript segments, resume text, job descriptions; no training on your data |
| Text to speech | Zoya's and Zia's voices | Text of what the agent says, transient |
| Telephony | Placing and recording Zoya's calls | Phone numbers, call audio |
| Email delivery | Interview invitations, follow-ups, scheduled reports | Recipient address and message content |
| Authentication | Sign-in for your team | Work email, sign-in events |
A named list of current providers is available on request and included in our data processing agreement. We notify customers before adding or replacing a provider that processes candidate data.
Compliance and your obligations
Under data protection law you are the controller of your candidates' data and XATZ is your processor. Here is how the responsibility splits.
- Data protection (GDPR, UK GDPR, DPDP)
- We process only on your instructions, under a data processing agreement, with the security measures on this page. You are responsible for having a lawful basis to process candidates' data and for informing them.
- AI transparency (EU AI Act)
- XATZ discloses AI involvement to candidates on every call and before every interview, as Article 50 requires. Autonomy levels keep a human reachable for every decision.
- Automated hiring tools (NYC Local Law 144, Illinois AIVIA, Maryland)
- XATZ provides the disclosure, consent and alternative-process steps these laws require, and clean exports so an independent auditor can perform a bias audit. Commissioning that audit and publishing results remains your obligation where the law applies.
- Certifications
- XATZ runs on infrastructure whose providers hold SOC 2 Type II and ISO 27001. XATZ's own SOC 2 programme is in progress. Ask us for the current status and a security questionnaire.
How do we handle incidents?
- Detection
- Continuous monitoring of access patterns, error rates and infrastructure health, with on-call engineering.
- Notification
- If we confirm a breach affecting your data, we notify your administrators without undue delay and within 72 hours, with what happened, what data was involved and what we are doing.
- Review
- Every incident ends with a written post-incident review shared with affected customers, including the changes made to prevent recurrence.
Report a vulnerability
We welcome reports from security researchers and act on them quickly.
Email security@xatz.us with the steps to reproduce. We acknowledge within two business days, keep you informed while we fix it, and credit you if you wish. Good-faith research that avoids accessing other customers' data and respects rate limits will not be met with legal action.
Privacy questions and data-subject requests: privacy@xatz.us
This page describes XATZ's practices as of 21 September 2026. It is not a contract. Contractual commitments are in your customer agreement and data processing agreement.