Security
Security is an engineering requirement at Hanzomon, not a page of promises. These are the practices behind the platform.
Data protection
All data is encrypted in transit and at rest. Access tokens and one-time codes are stored as SHA-256 hashes only — plaintext is never persisted, and cannot be recovered even by us.
Access control
Role-based access control governs every recruiter action, with organisation-level isolation and full audit logging of sensitive operations.
Assessment integrity
Session fingerprinting, anomaly detection, and immutable audit trails protect the validity of every result — the same audit trail we expose to your compliance team.
Reliability
Assessment generation and scoring run on durable, checkpointed workflows: a failure mid-process retries automatically and can never ship a half-built assessment.
Responsible disclosure
Found a vulnerability? Report it to [email protected] — we acknowledge within 48 hours and credit researchers who report in good faith.
Compliance alignment
Built for regulated hiring from day one.
GDPR
Explicit candidate consent, data minimisation, and built-in erasure (Art. 17).
NYC Local Law 144
Bias scanning with audit logging designed around AEDT audit requirements.
EU AI Act
Hiring AI is high-risk under Annex III — documentation, human oversight and logging built in.
SOC 2
On the certification roadmap; controls designed to Type II expectations.
Compliance tooling supports your obligations — it doesn't replace them. You should still run your own adverse-impact and legal review; H-Evaluate's contribution is generating the audit trail that makes that review possible.