Trust and compliance overview¶
This section is written for the people Legal, Security, and Procurement send SkillFoundry's way: it is the compliance story for a tool that touches candidate personal data and helps drive employment decisions. It documents what SkillFoundry does today, how each control maps to a regulatory requirement, where the shared responsibility line sits between SkillFoundry and the hiring organization, and — honestly — what is still on the roadmap.
How to read this section
Every claim below is tagged so you can tell commitments from current reality:
- In place — a control that exists in the product or operations today.
- Configurable — available, but off by default or dependent on your plan/settings.
- On request — provided under NDA or via your account contact (e.g. audit reports, the signed DPA).
- Roadmap — committed but not yet generally available. We would rather tell you than let you assume.
Nothing here is legal advice. Use it to brief your own counsel; the automated-employment-decision rules in particular (see Bias audits and adverse impact) impose obligations on you as the employer that SkillFoundry cannot discharge for you.
What SkillFoundry is, in data-protection terms¶
SkillFoundry is a technical skills assessment platform. Candidates complete realistic engineering tasks; hiring teams receive automated scores and a behavioral profile of how the candidate worked. See the platform overview and Monitoring and data collection for the product mechanics.
For most enterprise deployments, the roles under GDPR / UK GDPR are:
| Scenario | Controller | Processor |
|---|---|---|
| An organization runs assessments on its own candidates | The hiring organization | SkillFoundry |
| SkillFoundry markets, bills, and operates the platform itself (account data, telemetry for service improvement) | SkillFoundry | SkillFoundry's sub-processors |
| A self-serve candidate practices without an employer | SkillFoundry | — |
Under CCPA/CPRA, when SkillFoundry processes candidate data on your behalf it acts as a service provider, not a seller, of that data. The Data Processing Addendum makes these roles binding.
The shared responsibility model¶
Compliance for automated hiring is a joint effort. In short:
| Area | SkillFoundry provides | The hiring organization owns |
|---|---|---|
| Access & audit logging | Immutable audit trail of who did what, retained and exportable (see Access and audit logging) | Reviewing logs, provisioning/deprovisioning reviewers, least-privilege role assignment |
| Data retention & erasure | Configurable retention, DSAR tooling, deletion/anonymization mechanics (see Data retention and erasure) | Responding to your own candidates' requests, setting retention that matches your legal basis |
| Bias audit / adverse impact | Scoring transparency, exportable outcome data, a documented model of what the score measures (see Bias audits and adverse impact) | Commissioning the independent bias audit, publishing the summary, and giving candidate notice (e.g. NYC Local Law 144) |
| Security attestations | SOC 2 / ISO 27001 posture, penetration tests, sub-processor list (see Certifications and attestations) | Vendor risk assessment, your own certifications |
| Candidate transparency & appeal | Candidate-facing disclosures, access to their own data, a human-review/appeal path (see Candidate rights and appeals) | Deciding how automated scores factor into hiring, honoring appeals |
| Behavioral monitoring | Data minimization by design (activity, not content), sanitization, scoping (see Behavioral monitoring privacy model) | Works-council / employee-representative consultation, choosing a lawful basis, candidate consent where required |
Regulation-to-control map¶
| Requirement | Where it's addressed |
|---|---|
| GDPR / UK GDPR — lawfulness, DSARs, retention, DPIA, breach notice | Data retention and erasure, Behavioral monitoring privacy model, DPA |
| CCPA / CPRA — consumer rights, service-provider terms | Data retention and erasure, DPA |
| GDPR Art. 22 — automated decision-making, right to human review | Candidate rights and appeals |
| NYC Local Law 144 — AEDT bias audit, notice | Bias audits and adverse impact |
| EEOC / Title VII / four-fifths rule; EU AI Act (high-risk employment) | Bias audits and adverse impact |
| SOC 2 / ISO 27001 / access control / breach response | Certifications and attestations, Access and audit logging |
| Employee/works-council monitoring, EU co-determination | Behavioral monitoring privacy model |
Requesting compliance documents¶
The following are available to customers and active prospects under a mutual NDA. Contact your account team or security@skillfoundry.dev / privacy@skillfoundry.dev:
- Signed Data Processing Addendum (with Standard Contractual Clauses)
- Current SOC 2 report / ISO 27001 certificate (subject to program status — see Certifications and attestations)
- Sub-processor list and change-notification subscription
- Latest penetration test summary
- Security questionnaire responses (CAIQ / SIG)
- DPIA support pack for behavioral monitoring
A candid statement on gaps¶
We have deliberately documented gaps rather than papering over them, because that is what makes this section usable by counsel:
- Read-access audit events (a reviewer opening a specific candidate's report) are being rolled out across all read paths; write/administrative actions are already logged. See Access and audit logging.
- In-product adverse-impact reporting is on the roadmap; today SkillFoundry supports the required audit by exporting the raw outcome and (where the employer supplies it) demographic data for an independent auditor. See Bias audits and adverse impact.
- SOC 2 / ISO 27001 status is stated plainly, including whether a report is a Type I or Type II and what period it covers, in Certifications and attestations.