Security, privacy, and responsible AI for modern recruiting.
Marty protects candidate data, supports your compliance obligations, and gives security and legal teams the evidence they need.
- EU data residencyGermany, Ireland & Netherlands
- ISO 27001 certifiedBy TÜV Nord
- GDPR ready out of the boxDPA, SCCs, retention rules
- 99.99%
- Uptime SLAMeasured over 12 months
What you can check here
- DocumentsCertificates, reports, and legal paperwork, grouped by the team that asks for them.
- SecurityProtects the system — access, encryption, detection, and recovery.
- Privacy & complianceGoverns the data and the law — lifecycle, outreach rules, regulations.
- Responsible AIManages algorithmic risk — oversight, transparency, bias testing.
- Common questionsThe twelve we get asked most, and who to email for the rest.
Certifications, reports, and legal documents
Grouped by the team that usually asks for them. Nothing here is a self-serve download yet — the status on each row is what you can expect when you ask.
For security teams
- ISO 27001 certificateDownload
- Penetration test summaryUnder NDA
- Vulnerability disclosure policyRead
- Security white paperDownload
Ask and we’ll send what you need:
For legal and privacy teams
- Data processing agreementDownload
- Subprocessor listView
- Privacy policyRead
- Records of processingOn request
- DPIA materialsOn request
Ask and we’ll send what you need:
For AI governance teams
- AI documentation packEnterprise
- AI principlesRead
- Bias audit statementDownload
- Model and data governance overviewDownload
Ask and we’ll send what you need:
Controls that protect the system
A full-time security team runs the programme: defence in depth, aligned to ISO 27000. The full control register is below.
Control register
Active as of September 2026
- Device encryption
- All data stored locally on company devices is encrypted.
- Background checks
- Run before employment, within what local law permits.
- Secure remote access
- Administration happens only over a dedicated VPN, and short session timeouts plus context-aware rules mean only managed, hardened laptops reach internal systems.
- Security training
- Awareness training for everyone, plus role-specific training for engineers.
- Least privilege
- Named individual accounts only, reviewed annually; production access sits behind hardware security keys.
- Single sign-on and provisioning
- SAML 2.0 with Okta, Entra ID, and Google Workspace; SCIM keeps seats and roles in sync.
- Multi-factor authentication
- Available on every account and enforceable workspace-wide.
- Role-based permissions
- Granular roles down to the field level decide who sees which pipeline and which candidate data.
- Audit logs
- Exportable record of access, changes, and deletions.
- Encrypted in transit
- TLS 1.2 and 1.3 with the strongest available cipher, enforced by HSTS.
- Encrypted at rest
- AES-256 across databases, object storage, and backups.
- Password hashing
- Credentials are salted and hashed; never stored in plain text.
- Key management
- Keys held in a managed KMS with rotation and split access, plus customer-specific keys for sensitive fields such as salary.
- Data centre access control
- Hosting runs in ISO 27001-certified EU facilities with escorted, logged physical access.
- Environmental safeguards
- Fire detection and suppression, redundant power with UPS and generators, climate control.
- Tenant and environment isolation
- Logical separation at every layer, and production, staging, and test environments stay fully segregated.
- Network defence
- WAF, DDoS filtering, and DNSSEC in front of the application.
- Uptime SLA and status page
- A 99.99% uptime commitment, with real-time availability and incident history published publicly.
- Data redundancy
- Encrypted backups run hourly to weekly by data type, with point-in-time recovery.
- Infrastructure redundancy
- Multi-zone EU deployment with synchronous replicas and automatic failover.
- Auto-scaling
- Capacity follows load, so hiring peaks don’t degrade performance.
- Vulnerability scanning
- Continuous scanning of code, dependencies, and infrastructure, with severity-based remediation timelines and retesting before release.
- Penetration testing
- Annual external test plus internal testing through the year; summary available under NDA.
- Monitoring and detection
- Centralised logging across production with 24/7 alerting to on-call.
- Responsible disclosure
- A published policy and a triage commitment for good-faith researchers.
- Incident response plan
- Documented plan covering triage, containment, and post-mortem, rehearsed annually.
- Escalation path
- On-call rotation with a defined route to security and privacy leads.
- Customer notification
- Affected customers are notified in writing within 24 hours of discovery.
- Business continuity plan
- Policies for keeping customer-facing services running through a prolonged disruption.
- Disaster recovery plan
- Recovery procedures with agreed RTO and RPO targets, owned by the security lead.
- Restore testing
- Backups are restored on a schedule, not assumed to work.
- Due diligence
- Every subprocessor is reviewed for security and privacy before it touches customer data.
- Published subprocessor list
- Kept current, with advance notice of changes.
- Contractual safeguards
- Data processing terms and confidentiality obligations flow down to every vendor.
Partner security assessments
As a trusted integration partner, Marty undergoes annual scoped technical assessments conducted by industry leaders including Google and Microsoft to maintain our integration partnerships and ensure we meet their strict requirements.
- Annual scoped assessment covering API access, OAuth scopes, and data handling.
- Microsoft
- Annual scoped assessment against partner requirements for Entra ID and Graph integrations.
How candidate data is governed
Marty acts as processor. The product enforces the rules so your team doesn’t track them in a spreadsheet.
Candidate data lifecycle
Five stages, each enforced by the product
Collection
Every record stores where it came from and which recruiter added it.
Lawful basis
Legitimate interest, documented per record with the balancing test on file.
Retention
Retention windows per pipeline; records expire automatically.
Access
Export or correct a candidate’s data straight from their profile.
Deletion
Erasure removes the record, stops sequences, and issues proof.
Compliant outreach
Sourcing at scale only works if every message is lawful
- Suppression lists
- Block by candidate, company, or country across every sequence and seat.
- Instant opt-out
- One request stops all future outreach and logs the timestamp.
- Country-level rules
- Local outreach restrictions applied automatically by candidate location.
- Sending limits
- Per-channel daily caps, delays, and cooldowns keep volume acceptable.
Erasure, end to end
A real deletion request, start to finish.
Request received
09:12 · candidate portal
Identity verified
09:40 · automated
3 sequences stopped
09:41 · all channels
Records erased, proof issued
09:43 · certificate retained
Regulatory support
What the product does for each framework you’re asked about.
- GDPREU & UK
Automated privacy notices, retention windows, and deletion requests.
DPA available
- CCPA / CPRACalifornia
Data handling and policy access managed for Californian applicants.
Addendum in terms
- EU AI ActEU
Sourcing and evaluation treated as high-risk: documented, tested, human-decided.
Documentation pack
International data governance
Your data stays in Europe unless you choose otherwise.
- EU hosting
- Frankfurt primary, Dublin backups
- Standard contractual clauses
- In place with every subprocessor
- Transfer impact assessments
- Run before any transfer outside the EU or UK
- Subprocessor assessments
- Due diligence plus 30 days’ notice of changes
AI you can trust
Marty’s AI is built to make recruiters faster and more confident — not to replace their judgment. Every score is explainable, every decision is yours.
What AI does in Marty
- Surfaces and ranks candidates that match a role
- Drafts outreach messages a recruiter reviews before sending
- Summarises CVs and notes, with links to the source
What it never does
- Reject, shortlist, or hire without a person deciding
- Infer emotion, personality, or protected characteristics
- Train models on your workspace data
Recruiters stay in control
Marty AI does not make hiring decisions. Recruiters set the criteria, review every result, and make every call. The AI surfaces and ranks — you decide.
Proactive guardrails
PII is removed before AI processing. Marty flags EEO-sensitive inputs and warns against subjective criteria — so your process stays fair and defensible from the start.
Audited and compliant
Marty undergoes third-party bias auditing through BABL, with annual reviews and internal governance processes to ensure our AI meets the highest standards for responsible hiring.
Verified results
No black-box scoring. Every match score includes clear reasoning that recruiters can read, question, and edit — so your team always understands why a candidate ranked where they did.
Where recruiting sits under the AI Act
- UnacceptableSocial scoring, emotion inference. Banned — and not something Marty does.
- High-riskSourcing, screening, evaluation. This is where recruiting sits and where the obligations apply.
- LimitedChat and message drafting. Requires disclosure to the candidate.
- MinimalSpam filtering, deduplication. No additional obligations.
Application dates
- 1 Aug 2024Regulation entered into force
- 2 Feb 2025Prohibited practices and AI literacy obligations apply
- 2 Aug 2025General-purpose AI and governance rules apply
- 2 Aug 2026High-risk obligations for employment and recruiting systems apply
- 2 Aug 2027Remaining high-risk categories in regulated products apply
Dates reflect the published regulation. Marty’s AI documentation pack is available now so you can start your own assessment; it isn’t legal advice.
AI principles · Bias audit statementQuestions we get asked
Sorted the way security reviews usually run.
Still need something?
Our security team answers questionnaires within two business days.
security@marty.hrReady to run security review?
Get the full documentation pack and a walkthrough with our security lead.