Your ATS holds names, addresses, social security numbers, resumes, interview notes, and rejection reasons. A breach isn't just embarrassing—it can cost you millions in fines and destroy your employer brand.
Security isn't optional. Compliance isn't optional. And if you're evaluating an ATS that treats these as afterthoughts, run.
This guide covers everything you need to know: what security features matter, which compliance regulations apply, and how to evaluate whether an ATS vendor is trustworthy.
Essential Security Features
These are the baseline. If an ATS doesn't have these, it's not enterprise-ready.
Data Encryption
Data should be encrypted both in transit (when moving between systems) and at rest (when stored in databases).
What to Verify:
- ✓ TLS/SSL encryption for all data in transit (HTTPS everywhere)
- ✓ AES-256 encryption for data at rest (industry standard)
- ✓ Encrypted backups with separate key management
- ✓ No plain-text passwords stored anywhere
SOC 2 Type II Certification
SOC 2 is an independent audit that verifies a company's security controls. Type II means they've been tested over time (6+ months), not just on one day.
Why It Matters:
- → Third-party auditors verify security practices
- → Tests security over time, not just at one moment
- → Required by many enterprise customers
- → Shows vendor takes security seriously
Red Flag:
"We're SOC 2 compliant" without providing the actual report. Always ask for proof.
Two-Factor Authentication (2FA)
Passwords alone aren't enough. 2FA adds a second layer of protection against account takeovers.
Must Support:
- ✓ SMS codes (basic, but better than nothing)
- ✓ Authenticator apps (Google Authenticator, Authy)
- ✓ Enforced for all users (not just optional)
Role-Based Access Control (RBAC)
Not everyone on your team needs to see everything. RBAC lets you control who can view, edit, or delete candidate data.
Examples:
- • Hiring Manager: Can view candidates for their department only
- • Recruiter: Can view all candidates, edit stages, send emails
- • Interviewer: Can view assigned candidates, add feedback
- • Admin: Full access including settings and exports
Audit Logs
Track who accessed what data and when. Critical for compliance and investigating potential breaches.
Should Log:
- • User logins and failed login attempts
- • Data exports (who downloaded candidate data?)
- • Permission changes
- • Candidate data edits and deletions
- • Integration access
Compliance Requirements
Depending on where you hire and what industry you're in, these regulations may apply to you.
| Regulation | Who It Applies To | Key Requirements |
|---|---|---|
| GDPR | Any company hiring EU residents | Right to access, delete, and export data; explicit consent required |
| CCPA | Companies hiring California residents | Right to know what data is collected; right to delete; opt-out of sale |
| EEOC | US employers with 15+ employees | No discrimination; keep hiring records 1 year; adverse action documentation |
| OFCCP | Federal contractors ($50k+ contracts) | Affirmative action; adverse impact analysis; 2-year record retention |
| HIPAA | Healthcare industry hiring | Protected health info security; limited access; breach notification |
Deep Dive: GDPR Compliance
If you hire anyone in the EU—even remote workers—GDPR applies. Non-compliance can cost up to 4% of global revenue.
Your ATS Must Support:
- ✓ Data export on request
- ✓ Complete data deletion
- ✓ Explicit consent tracking
- ✓ Processing purpose logs
You Must Provide:
- → Privacy policy on careers page
- → Consent checkbox on applications
- → Data retention policy
- → Process to handle requests
Deep Dive: EEOC Compliance
The Equal Employment Opportunity Commission requires you to keep hiring records and avoid discriminatory practices.
Record Retention Requirements:
- • Keep all applicant records for 1 year
- • Keep hired employee records for duration + 1 year
- • Federal contractors: 2 years minimum
Watch Out For:
- • Resume screening keywords that could be discriminatory
- • Interview questions about age, religion, marital status
- • Lack of documentation for rejection reasons
- • Adverse impact in hiring decisions
Security Built In, Not Bolted On
EasyApply is SOC 2 Type II certified with enterprise-grade security. GDPR and CCPA compliant out of the box.
Start Free Trial →Data Retention Policies
How long should you keep candidate data? Too short and you violate EEOC. Too long and you violate GDPR.
Recommended Retention Schedule
Active Candidates
Keep until rejected, withdrawn, or hired
Rejected Candidates (US)
1 year from rejection (EEOC requirement)
Rejected Candidates (EU)
6 months unless candidate consents to longer
Hired Employees
Duration of employment + 1 year (EEOC) or up to 7 years (some states)
Talent Pool / Pipeline
Explicit opt-in required; honor unsubscribe immediately
ATS Must-Have:
Automated data retention policies that delete candidate data after your specified period. Manual deletion doesn't scale and creates compliance risk.
Ask your ATS vendor: "Can you automatically delete candidate data after 1 year per EEOC requirements?"
Evaluating ATS Security
Don't just take a vendor's word for it. Here's how to verify their security claims.
Questions to Ask in Sales Demos:
Security Red Flags
Run—don't walk—if you encounter any of these:
-
🚩
"We take security seriously" without providing proof (SOC 2, penetration test results, etc.)
-
🚩
No 2FA option or 2FA only for admins
-
🚩
"GDPR compliant" but can't explain how they handle deletion requests
-
🚩
Unclear data ownership in terms of service
-
🚩
No data export or export costs extra
-
🚩
Vague answers about where data is stored
-
🚩
No audit logs or logs only retained for 30 days
Average cost of a data breach in 2023
Source: IBM
Maximum GDPR fine (or 4% global revenue)
Whichever is higher
Average time to identify and contain a breach
Source: IBM
Enterprise Security, Startup Simplicity
EasyApply is SOC 2 Type II certified with GDPR and CCPA compliance built in. Bank-level encryption, 2FA, role-based access—all standard.
No credit card required. SOC 2 report available on request.