Canadian data residency
Security and trust,
built into every screen
WorkSignal handles sensitive candidate data - voice recordings, resumes, assessments. Here is exactly how we protect it.
Encryption everywhere
All data is encrypted in transit using TLS 1.2+ and at rest using industry-standard AES-256 encryption. Voice recordings, transcripts, resumes, and assessment data are all encrypted at the storage level.
- TLS 1.2+ for all connections
- AES-256 encryption at rest
- No credentials stored in source code
Canadian data residency
All primary data processing and storage happens in Canada. Our infrastructure runs on DigitalOcean's Toronto (TOR1) data center region, keeping candidate data within Canadian jurisdiction.
- Toronto, Canada data center
- PIPEDA-compliant data handling
- Canada recognized as adequate by EU Commission
Access controls
Access to production systems is restricted to authorized personnel only. Every access attempt is logged and reviewed. Customer data is isolated at the organization level with tenant-scoped queries enforced at the model layer.
- Multi-tenant data isolation
- Role-based access controls
- Full audit logging of all actions
AI data handling
Candidate data sent to AI providers is covered by data processing agreements. AI-generated outputs are recommendations only - humans make all final hiring decisions. Your candidate data is never used to train third-party models.
- Data processing agreements with all AI providers
- No model training on your data
- Human-in-the-loop for all hiring decisions
Candidate consent at every step
WorkSignal collects explicit consent before any AI interaction. The consent requirements adapt based on the candidate's jurisdiction - Ontario, Illinois, Texas, NYC, and others each have different rules. Our system applies the right ones automatically.
Application
AI disclosure shown on the job posting. Candidate agrees to data processing when applying.
Scheduling
Jurisdiction-specific consent collected before scheduling. AI screening, recording, and biometric consent where required.
Voice screen
AI identifies itself at the start of every call. Recording notice and opt-out option provided verbally.
Post-screen
Human reviews all AI assessments. Candidates can request human review if they believe the AI assessment was unfair.
Subprocessors
These are the third-party services that process customer or candidate data on our behalf. Each operates under a data processing agreement.
| Provider | Purpose | Location |
|---|---|---|
| DigitalOcean | Cloud infrastructure and data storage | Toronto, Canada |
| Stripe | Payment processing (PCI DSS compliant) | United States |
| ElevenLabs | structured interview calls | United States |
| Retell AI | structured interview calls (backup provider) | United States |
| OpenAI | Resume analysis and candidate assessment | United States |
| Anthropic | AI-powered candidate evaluation | United States |
| Resend | Transactional email delivery | United States |
| Twilio | SMS notifications and phone number verification | United States |
| Umami | Privacy-focused analytics (no cookies, no PII) | Self-hosted, Canada |
Data retention
We retain data only as long as needed to provide the service and meet legal obligations.
Account data
Duration of active account + 90 days after closure
Candidate data
Duration of recruiter's active account
Voice recordings & transcripts
Up to 1 year, or until recruiter deletes - whichever is sooner
Compliance records
3 years minimum (Ontario Bill 149 record retention requirement)
Payment & billing
7 years (CRA requirement)
Server logs
Up to 90 days
Compliance roadmap
We are building toward formal certifications alongside our existing compliance infrastructure.
PIPEDA compliance
Canadian federal privacy law. Express consent for sensitive data, implied for less-sensitive. In effect.
Ontario Bill 149 automation
AI disclosure, salary validation, content scanning, 45-day notification tracking. Live and enforced in-product.
Multi-jurisdiction consent engine
Jurisdiction-aware consent collection covering Ontario, Quebec, BC, Illinois, Texas, NYC, California, and GDPR. Live.
SOC 2 Type II
Planned. Formal observation period and audit to follow in 2026-2027.
Documents
Need a Data Processing Agreement (DPA)? Contact us below.
Security contact
For security inquiries, vulnerability reports, DPA requests, or to request our security questionnaire responses, contact us at:
security@worksignal.comReady for a compliant, auditable hiring process?
Talk to our team about your security and compliance requirements.