Trust
Security and trust
Trust is part of the process.
Protect candidate information and give your teams the access they need. Elevator by Superset brings together enterprise security controls, clear permissions and a record of the actions taken throughout hiring.
Certified and audited
Aligned with India’s DPDP Act 2023. Half-yearly third-party penetration testing with re-test. Superset’s GDPR statement and security policy apply to Elevator in full.
Four pillars
Ready for your security review.
Explore certifications, access controls, data protection and the documentation available to your security and procurement teams.
-
Certifications and testing
SOC 2 attested, ISO 27001 certified, GDPR compliant. Half-yearly third-party penetration testing with re-test, and an executive summary you can share.
-
Access and identity
Single sign-on over SAML 2.0 and OIDC, enforceable tenant-wide. SCIM 2.0 provisioning, multi-factor authentication, and seven roles across 43 capabilities.
-
Data protection
Encrypted in transit and at rest on AWS. Document store and database encrypted independently, with managed keys and rotation. Candidate data is never used to train a model.
-
Governance and evidence
An append-only audit log, a retention schedule with a working erasure queue, a sub-processor register derived from what is connected, and support access that leaves a trace.
Role-based access
Give each person the right access.
Seven roles cover 43 capabilities, with full, scoped or no access for each. Permissions determine which records a person can query, helping hiring managers, finance partners and recruiters work within their responsibilities.
What’s included
- Roles: recruiter, recruiting coordinator, hiring manager, interviewer, finance approver, HR business partner, administrator
- Each role mapped to a directory group, so joiners and leavers are handled by your identity team
- Access control is never a model’s call: a probabilistic answer here is simply a breach
Identity
Connect access to your company directory.
Use SAML 2.0 or OIDC single sign-on with your identity provider. SCIM provisioning supports account creation, updates and deactivation, with directory groups mapped to roles and multi-factor authentication available.
What’s included
- SSO via SAML 2.0 and OIDC, enforceable tenant-wide
- SCIM 2.0 provisioning and deprovisioning from your directory
- Multi-factor authentication
Audit, retention and erasure
Put data policies into practice.
Use retention schedules and an erasure queue to manage candidate data requests. An append-only audit log records changes with the actor, timestamp and previous values, supporting review by your security and privacy teams.
What’s included
- Append-only audit log, filterable and exportable, per requisition, candidate, interview and offer
- Retention schedule with automatic triggers, and an erasure queue with owner, due date and completion on the record
- Consent, purpose limitation and erasure handled the same way whichever law applies
Sub-processors
Know where candidate data is shared.
Review a sub-processor register based on the systems connected to your organisation. See which services receive candidate information and the purpose of each connection.
What’s included
- Derived from connected systems, not maintained separately
- Each entry states what data flows to it and which connector sends it
- Included in the security pack shared during procurement, alongside residency
Support access
Keep support access accountable.
Support access is time-limited and linked to a ticket. Actions taken by the engineer appear in your audit log, giving your team visibility into the work carried out in your environment.
What’s included
- Time-boxed, expires on its own
- Linked to a support ticket you can see
- Every action recorded in your audit log, with the support engineer as the named actor
What is included
In security and trust
- SOC 2 attested, ISO 27001 certified, GDPR compliant
- Aligned with India’s DPDP Act 2023: consent, purpose limitation, retention schedules, a working erasure queue
- Half-yearly third-party VAPT with re-test and a shareable executive summary
- SSO via SAML 2.0 and OIDC (Okta, Microsoft Entra ID, Google Workspace, any compliant IdP), enforceable tenant-wide
- SCIM 2.0 provisioning with each role mapped to a directory group
- Multi-factor authentication
- Role-based access: seven roles, 43 capabilities, each full, scoped or none
- Scoping enforced at query level, not in the interface
- Encryption in transit and at rest; document store and database encrypted independently
- Managed keys with rotation, hosted on AWS
- Append-only audit log with actor, timestamp and before-and-after
- Data retention schedule and right-to-erasure queue
- Sub-processor register derived from connected systems
- Break-glass support access: time-boxed, ticket-linked, recorded in your audit log
- Candidate data is never used to train a model
The full security pack, including data residency, the current sub-processor list and the latest penetration-test summary, is shared during procurement. Superset’s corporate security policy and GDPR statement apply to Elevator.
Security and trust, answered
Is Elevator SOC 2 and ISO 27001 certified?
Where is candidate data hosted?
Is Elevator GDPR compliant?
Does Elevator use candidate data to train AI?
How is access controlled?
How are erasure requests handled?
Can Superset staff see our data?
Your next team starts here
Your hiring.
All together.
A walkthrough of Elevator, shaped around your roles, your people and your process.