Docs/Features/Security
Additional

Security & Compliance

Enterprise-grade security with SOC 2 Type II certification, GDPR compliance, and complete audit trails.

SOC 2 Type II

Independently audited security controls.

Encryption

AES-256 at rest, TLS 1.3 in transit.

Audit Trail

Complete log of all actions and access.

GDPR Ready

Data portability, erasure, and consent tools.

Security & Compliance

SOC 2 Type II certified
GDPR compliant
CCPA compliant
Data encrypted at rest (AES-256)
Data encrypted in transit (TLS 1.3)
SSO via SAML 2.0 / OAuth
Two-factor authentication
Role-based access control

Frequently Asked Questions

Is Prepzo SOC 2 compliant?

Yes. Prepzo is SOC 2 Type II certified, meaning our security controls have been audited and verified by independent auditors. We undergo annual re-certification to maintain this standard.

How is candidate data protected?

All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Data is stored in secure cloud infrastructure with geographic redundancy. Access is strictly controlled through role-based permissions.

Is Prepzo GDPR compliant?

Yes. Prepzo supports GDPR requirements including: data subject access requests, right to erasure, data portability, consent management, and data processing agreements. EU data can be stored in EU regions.

Does Prepzo support SSO?

Yes. Scale plan and above includes SSO support via SAML 2.0 and OAuth. We integrate with Okta, Azure AD, Google Workspace, and other identity providers.

What is the audit trail?

Every action in Prepzo is logged: who did what, when, and from where. Admins can review audit logs to track candidate data access, profile changes, login events, and permission modifications.

How does role-based access work?

Assign team members roles (Admin, Hiring Manager, Recruiter, Viewer) with predefined permissions. Create custom roles for specific needs. Restrict access to specific jobs for confidential hiring.

Can I control who accesses sensitive data?

Yes. Sensitive fields like salary expectations can be restricted to specific roles. You can also enable two-factor authentication for all users and require SSO for enhanced security.

What happens to data when I delete it?

Deleted candidate data is soft-deleted first (recoverable for 30 days), then permanently purged from all systems including backups. You can request immediate hard deletion for GDPR compliance.