Security and data handling
A hiring system holds résumés, contact details, interview notes, and scorecards for people who applied to your company. Here is where that data goes, who touches it, what the AI does with it, and how you get it back.
Every question below has an answer you can check
The answers below come from four published documents: the Privacy Policy, the Terms, the published Sub-processors list, and the Data Processing Addendum, which is published in full.
If your security reviewer needs something this page does not cover, the answer is a conversation, not a gate. Where your data goes, who processes it, what the AI does with it, how long it is kept, and how you get it back are the parts you can settle on your own.
Where your candidate data lives
Yardstick hosts the Services in the United States.
| What | Where it runs | What it holds |
|---|---|---|
| Database, authentication, file storage | Supabase, on AWS us-east-2 (Ohio) | Candidate records, roles, interviews, scorecards, uploaded résumés, account identifiers |
| Application hosting and CDN | Vercel, iad1 (Washington, D.C.) with a global edge CDN | Data in transit through the product, request metadata and logs |
| Billing | Stripe | Billing contact details. Card data goes directly to Stripe, and Yardstick stores only the last four digits |
Data is encrypted in transit using TLS, and encrypted at rest using AES-256 through Supabase. Database backups run daily and are encrypted at rest with AES-256, with point-in-time recovery available where the database provider supports it.
Yardstick's development process includes automated database security linting and AI-assisted review of code changes. That measure, like the encryption and backup measures above, is written into the Privacy Policy and the DPA your reviewer can read.
The table above is the infrastructure, not the whole list. You can see every sub-processor that processes your data, what each one receives, and the region it processes in, on the published Sub-processors page, with a link to each vendor's own privacy and data-processing terms. Regions there reflect the current configuration, and where a sub-processor may process data in another region, the page says so.
What happens when the AI reads a résumé
Knowing where the data sits only gets you so far. The question your reviewer will actually stop on is what the AI does with it, so here is that answer in full.
Yardstick does not train models on your data. Yardstick does not use customer-identifiable personal information to train or retrain its own models, and it uses paid API tiers with data-processing terms in place, under which the providers represent that data submitted to them is not used to train or improve theirs. What Yardstick does use is aggregated, de-identified data, which no longer identifies anyone, to improve the Services and the quality of its AI features. The Privacy Policy draws the line in those words.
Every provider that can see it is named. Yardstick currently uses Google Gemini for the AI features in the product. When you generate interview questions, a scorecard, or an interview plan, the text you submit goes to the generative-AI sub-processor serving that request and the result comes back. Anthropic and OpenAI are also on the Sub-processors page, listed for optional drafting assistance and for the AI-assisted development and support tooling described below. That page gives each one its own row: what it receives, the region it processes in, and a link to its terms. Your reviewer does not have to guess which companies can see what you submit, and does not have to email anyone to find out.
Applications are evaluated against the criteria you set. Alongside drafting, Yardstick's AI can read incoming applications against the job-related criteria you defined for that role, and produce suggested scores or a ranking, so your team has somewhere to start when a lot of people apply. It is there to help you prioritize. The score is a suggestion your team reads, not a cutoff and not a decision, and it is not by itself a reason anyone is rejected. The Privacy Policy describes this the same way, and records those scores as inferences in the CCPA notice.
What Yardstick does look at is the output. Yardstick analyzes the results its AI features produce, to improve the prompts it uses and to pick the models that perform best, and it uses aggregated, de-identified data to improve the product, including the quality of its AI features. Both are written into the Terms, in the AI model usage section your reviewer can read.
Each provider keeps its own retention practices, which Yardstick does not control. The provider links on the sub-processors page go to the terms that govern it.
A person still decides. Yardstick's AI features produce drafts, summaries, and suggestions for a human on the hiring team to review. The product does not automatically reject, screen out, or disqualify a candidate without human review, and Yardstick does not make hiring decisions on its own. Because you decide which roles to hire for, which criteria to apply, and what to do with any output, you are the controller of that processing and Yardstick is your processor.
No audio or video recording. Yardstick's interview features are text-based. Yardstick does not record or collect audio or video interviews, and does not analyze either.
Sensitive attributes are not something the product asks for. Yardstick is not designed to collect special-category or sensitive data and does not request it. Free-text fields like résumés and notes can contain anything a person writes, so Yardstick's AI features are designed to work from the job-related criteria you define rather than to use sensitive attributes as an input.
AI development tools get read-only production access. Yardstick's engineers use AI-assisted development tools that can be granted read-only access to production databases to diagnose a problem. Those tools run under provider terms that disable training on submitted data, and access is limited to what is needed to resolve the issue.
Yardstick people get access to your account when you ask them in. Separately from those tools, Yardstick personnel may be granted access to your account at your request, for example by being added as a user, to help configure the Services, provide onboarding or support, or advise you, and in that work they may come into contact with your data. Both paths are set out in the Privacy Policy, under AI-assisted development and support tools and under support and setup access.
Who can reach it
Every sub-processor Yardstick uses is listed in full on the Sub-processors page, including the ones the table above does not name, like Resend, which delivers transactional email. Services you connect yourself are a separate matter and stay under your control: the Privacy Policy covers them under third-party integrations, and they are not Yardstick sub-processors. The other list is people, and it is short on both sides of the line.
Inside Yardstick, access to systems holding personal information is role-based and least-privilege, limited to the staff who need it. Multi-factor authentication is required for staff to reach those systems, and access to them is logged. Customer data is separated by customer account at the database layer, where access is constrained by database-enforced controls rather than by application code alone (Privacy Policy, “How We Keep Your Personal Information Secure”).
On your side of the line:
- Sign-in — email and password, or single sign-on through Google or Microsoft.
- Multi-factor authentication is available to your users as a product feature.
- Your own agent — Yardstick has a public API on every account, so a coding agent running the
yardstickCLI can work your pipeline (how that works). The Terms are explicit about where that leaves you: you stay responsible for everything done through your credentials or by agents acting on your behalf, and you are responsible for making sure agent-assisted work gets your team's review and approval. The product is built to make that straightforward. An agent prepares the sensitive actions and a person on your team confirms them: advancing or rejecting a candidate, publishing a job, sending candidate email outside an approved sequence, and changing permissions, API tokens, or billing.
Getting your data out, and getting it deleted
You control retention of candidate data, not Yardstick. There is no fixed schedule on which Yardstick deletes it out from under you.
- While you are a customer — you and your authorized users can generally access, export, correct, and delete candidate data from inside the platform.
- Cancelling a paid plan does not delete anything. Your account continues with paid features unavailable, your closed or archived hiring history generally stays available to read as described on the pricing page, and your data stays until you delete it.
- When you delete your account, or an enterprise agreement ends, your data stays available read-only for at least 30 days so you can export it. Yardstick then holds it for at least another 30 days before permanently deleting it from active systems, and if you need longer to export, you can ask. Residual copies in routine backups are removed on the standard backup cycle after that, except where the law requires them kept.
- Deleting a single record removes it from active systems and from backups on the standard backup-expiry cycle.
Teams reading this are often mid-migration, planning what moves in and what has to be able to move back out. Switching to Yardstick covers the import side.
Separately from candidate data, Yardstick keeps operational records of how signed-in users move through the product, which screens they reached and whether an action succeeded. Those records do not include what you write, résumés, application materials, or message text, and they are kept for no longer than six months.
To ask about any of this, or to exercise a data-protection right, the address is privacy@yardstick.team.
SOC 2: what Yardstick holds, and what it runs on
Yardstick runs on infrastructure providers with independently certified security programs. The certifications below are the providers'; Yardstick does not yet hold a SOC 2 of its own.
| Provider | What it runs | Certifications |
|---|---|---|
| Supabase | Database, authentication, file storage | SOC 2 Type 2, ISO 27001 |
| Vercel | Hosting and content delivery | SOC 2 Type 2, ISO 27001:2022, certified under the EU-U.S. Data Privacy Framework |
Those attestations are the providers' own, and you can verify each one directly with the provider. Every provider on the Sub-processors page is listed with links to its privacy and data-processing terms.
On testing, the DPA commits Yardstick to performing or commissioning third-party penetration testing where reasonably required, for example at an Enterprise customer's request. If your procurement process requires a vendor's own SOC 2 report, bring it to a call.
You find out when something changes
A vendor review is a snapshot. Two commitments in the DPA keep it current after you sign.
You get advance notice before a new sub-processor touches your data. The DPA commits Yardstick to at least thirty days' notice before a new or replacement sub-processor begins processing customer personal data, and it names the mechanism: the Sub-processors page and its subscribable change feed are the channel of record. The page also carries a dated change log, so you do not have to re-read it to notice a new vendor. The one exception is published too: if a sub-processor has to be replaced on an emergency basis, because it stops operating or a security issue needs immediate action, the change can happen straight away and notice goes out promptly afterward. Your right to object is the same either way.
Incidents come to you. For candidate data and other customer data, where Yardstick acts as your processor, Yardstick notifies you without undue delay after becoming aware of a personal data breach, and provides what it has so you can meet your own notification obligations. Where Yardstick is the controller, for site visitors, account holders, and billing contacts, it notifies affected people and regulators within the periods the law requires, including the GDPR's 72 hours where feasible.
The paperwork, published: DPA, Privacy Policy, Terms
- Data Processing Addendum — published in full and incorporated into the Terms. You do not have to request it or sign an NDA to read it.
- Privacy Policy — the complete account, including candidate rights and the AI section this page summarizes.
- Terms of Service — including the AI model usage and confidentiality sections.
- Sub-processors — the current list, the change log, and the change feed.
- Cookie Notice — analytics on this website are off until you opt in, and Yardstick does not currently use advertising, marketing, or cross-context personalization cookies.
For EEA and UK data, safeguards include the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum with the sub-processors that process your personal information, or another lawful transfer mechanism. Yardstick does not sell personal data.
Common security and data questions
Does Yardstick train AI models on our candidate data?
No. Yardstick does not use customer-identifiable personal information to train or retrain its own models, and it uses paid API tiers under data-processing terms in which the providers represent that submitted data is not used to train theirs. Aggregated, de-identified data, which no longer identifies anyone, is used to improve the Services, including the quality and accuracy of the AI features.
Is Yardstick SOC 2 certified?
No. Yardstick does not currently hold its own SOC 2 or equivalent certification. It relies on infrastructure providers with independently certified programs: Supabase (SOC 2 Type 2, ISO 27001) and Vercel (SOC 2 Type 2, ISO 27001:2022, EU-U.S. Data Privacy Framework).
Where is candidate data stored?
Yardstick hosts the Services in the United States. The database, authentication, and file storage run on Supabase on AWS us-east-2 (Ohio), and application hosting runs on Vercel in iad1 (Washington, D.C.). Each sub-processor's processing region is listed on the sub-processors page, and some may process data in other regions as described there.
Which AI providers does Yardstick send data to?
Yardstick currently uses Google Gemini. Anthropic and OpenAI are also listed as sub-processors, for optional drafting assistance and for the AI-assisted development and support tooling Yardstick's engineers use. The sub-processors page lists what each one receives, the region it processes in, and a link to its terms.
Is candidate data encrypted?
Yes. In transit with TLS, and at rest with AES-256 through Supabase. Database backups run daily and are encrypted with AES-256, with point-in-time recovery available where the database provider supports it.
Can we export our data?
Yes. You and your authorized users can generally access, export, correct, and delete candidate data from inside the platform.
What happens to our data if we cancel?
Cancelling a paid plan does not delete anything; your account continues with paid features unavailable, and your closed or archived hiring history generally remains readable as described on the pricing page. If you delete your account, your data stays available read-only for at least 30 days so you can export it, and Yardstick holds it for at least another 30 days before permanently deleting it from active systems.
Does Yardstick's AI reject or screen out candidates automatically?
No. Yardstick's AI can read incoming applications against the job-related criteria you define and produce suggested scores or a ranking, to help your team prioritize. It is decision support: a score is a suggestion your team reads, not a cutoff. It does not automatically reject, screen out, or disqualify a candidate without human review, and Yardstick does not make hiring decisions on its own. Because you decide which roles to hire for, which criteria to apply, and what to do with any output, you are the controller of that processing and Yardstick is your processor.
Does Yardstick record or analyze video interviews?
No. Yardstick's interview features are text-based. There is no audio or video recording and no analysis of either.
Will Yardstick sign a DPA?
The Data Processing Addendum is published in full at yardstick.team/dpa and incorporated into the Terms.
How do we find out if a sub-processor changes?
The DPA commits Yardstick to at least thirty days' advance notice before a new or replacement sub-processor begins processing customer personal data. Notice is given through the sub-processors page and its subscribable change feed, which the DPA names as the channel of record. The page also carries a dated change log. If a sub-processor has to be replaced on an emergency basis, the DPA allows the change to be made immediately with notice published promptly afterward, and your right to object is unchanged.
Does Yardstick do penetration testing?
The DPA commits Yardstick to performing or commissioning third-party penetration testing where reasonably required, for example at an Enterprise customer's request.
Bring the questions this page did not answer.
Your security reviewer will have some. Book a call and get them answered directly, without a questionnaire portal in between. Or see it for yourself first: you can run your first three jobs free and watch exactly what the product stores before you commit to a paid plan.
.webp?dpl=dpl_FqSMREfvMqPiPUwwYq2egBpxVGYQ)