Back to home

Security

Security is an engineering requirement at Hanzomon, not a page of promises. These are the practices behind the platform.

Data protection

All data is encrypted in transit and at rest. Access tokens and one-time codes are stored as SHA-256 hashes only — plaintext is never persisted, and cannot be recovered even by us.

Access control

Role-based access control governs every recruiter action, with organisation-level isolation and full audit logging of sensitive operations.

Assessment integrity

Session fingerprinting, anomaly detection, and immutable audit trails protect the validity of every result — the same audit trail we expose to your compliance team.

Reliability

Assessment generation and scoring run on durable, checkpointed workflows: a failure mid-process retries automatically and can never ship a half-built assessment.

Responsible disclosure

Found a vulnerability? Report it to [email protected] — we acknowledge within 48 hours and credit researchers who report in good faith.

Compliance alignment

Built for regulated hiring from day one.

GDPR

Explicit candidate consent, data minimisation, and built-in erasure (Art. 17).

NYC Local Law 144

Bias scanning with audit logging designed around AEDT audit requirements.

EU AI Act

Hiring AI is high-risk under Annex III — documentation, human oversight and logging built in.

SOC 2

On the certification roadmap; controls designed to Type II expectations.

Compliance tooling supports your obligations — it doesn't replace them. You should still run your own adverse-impact and legal review; H-Evaluate's contribution is generating the audit trail that makes that review possible.