Skip to content

Trust and compliance overview

This section is written for the people Legal, Security, and Procurement send SkillFoundry's way: it is the compliance story for a tool that touches candidate personal data and helps drive employment decisions. It documents what SkillFoundry does today, how each control maps to a regulatory requirement, where the shared responsibility line sits between SkillFoundry and the hiring organization, and — honestly — what is still on the roadmap.

How to read this section

Every claim below is tagged so you can tell commitments from current reality:

  • In place — a control that exists in the product or operations today.
  • Configurable — available, but off by default or dependent on your plan/settings.
  • On request — provided under NDA or via your account contact (e.g. audit reports, the signed DPA).
  • Roadmap — committed but not yet generally available. We would rather tell you than let you assume.

Nothing here is legal advice. Use it to brief your own counsel; the automated-employment-decision rules in particular (see Bias audits and adverse impact) impose obligations on you as the employer that SkillFoundry cannot discharge for you.

What SkillFoundry is, in data-protection terms

SkillFoundry is a technical skills assessment platform. Candidates complete realistic engineering tasks; hiring teams receive automated scores and a behavioral profile of how the candidate worked. See the platform overview and Monitoring and data collection for the product mechanics.

For most enterprise deployments, the roles under GDPR / UK GDPR are:

Scenario Controller Processor
An organization runs assessments on its own candidates The hiring organization SkillFoundry
SkillFoundry markets, bills, and operates the platform itself (account data, telemetry for service improvement) SkillFoundry SkillFoundry's sub-processors
A self-serve candidate practices without an employer SkillFoundry —

Under CCPA/CPRA, when SkillFoundry processes candidate data on your behalf it acts as a service provider, not a seller, of that data. The Data Processing Addendum makes these roles binding.

The shared responsibility model

Compliance for automated hiring is a joint effort. In short:

Area SkillFoundry provides The hiring organization owns
Access & audit logging Immutable audit trail of who did what, retained and exportable (see Access and audit logging) Reviewing logs, provisioning/deprovisioning reviewers, least-privilege role assignment
Data retention & erasure Configurable retention, DSAR tooling, deletion/anonymization mechanics (see Data retention and erasure) Responding to your own candidates' requests, setting retention that matches your legal basis
Bias audit / adverse impact Scoring transparency, exportable outcome data, a documented model of what the score measures (see Bias audits and adverse impact) Commissioning the independent bias audit, publishing the summary, and giving candidate notice (e.g. NYC Local Law 144)
Security attestations SOC 2 / ISO 27001 posture, penetration tests, sub-processor list (see Certifications and attestations) Vendor risk assessment, your own certifications
Candidate transparency & appeal Candidate-facing disclosures, access to their own data, a human-review/appeal path (see Candidate rights and appeals) Deciding how automated scores factor into hiring, honoring appeals
Behavioral monitoring Data minimization by design (activity, not content), sanitization, scoping (see Behavioral monitoring privacy model) Works-council / employee-representative consultation, choosing a lawful basis, candidate consent where required

Regulation-to-control map

Requirement Where it's addressed
GDPR / UK GDPR — lawfulness, DSARs, retention, DPIA, breach notice Data retention and erasure, Behavioral monitoring privacy model, DPA
CCPA / CPRA — consumer rights, service-provider terms Data retention and erasure, DPA
GDPR Art. 22 — automated decision-making, right to human review Candidate rights and appeals
NYC Local Law 144 — AEDT bias audit, notice Bias audits and adverse impact
EEOC / Title VII / four-fifths rule; EU AI Act (high-risk employment) Bias audits and adverse impact
SOC 2 / ISO 27001 / access control / breach response Certifications and attestations, Access and audit logging
Employee/works-council monitoring, EU co-determination Behavioral monitoring privacy model

Requesting compliance documents

The following are available to customers and active prospects under a mutual NDA. Contact your account team or security@skillfoundry.dev / privacy@skillfoundry.dev:

  • Signed Data Processing Addendum (with Standard Contractual Clauses)
  • Current SOC 2 report / ISO 27001 certificate (subject to program status — see Certifications and attestations)
  • Sub-processor list and change-notification subscription
  • Latest penetration test summary
  • Security questionnaire responses (CAIQ / SIG)
  • DPIA support pack for behavioral monitoring

A candid statement on gaps

We have deliberately documented gaps rather than papering over them, because that is what makes this section usable by counsel:

  • Read-access audit events (a reviewer opening a specific candidate's report) are being rolled out across all read paths; write/administrative actions are already logged. See Access and audit logging.
  • In-product adverse-impact reporting is on the roadmap; today SkillFoundry supports the required audit by exporting the raw outcome and (where the employer supplies it) demographic data for an independent auditor. See Bias audits and adverse impact.
  • SOC 2 / ISO 27001 status is stated plainly, including whether a report is a Type I or Type II and what period it covers, in Certifications and attestations.