Security & Trust - WorkSignal
Canadian data residency

Security & Trust

WorkSignal handles sensitive candidate data - voice recordings, resumes, assessments. Here is exactly how we protect it.

Encryption everywhere

All data is encrypted in transit using TLS 1.2+ and at rest using industry-standard AES-256 encryption. Voice recordings, transcripts, resumes, and assessment data are all encrypted at the storage level.

  • TLS 1.2+ for all connections
  • AES-256 encryption at rest
  • No credentials stored in source code

Canadian data residency

All primary data processing and storage happens in Canada. Our infrastructure runs on DigitalOcean's Toronto (TOR1) data center region, keeping candidate data within Canadian jurisdiction.

  • Toronto, Canada data center
  • PIPEDA-compliant data handling
  • Canada recognized as adequate by EU Commission

Access controls

Access to production systems is restricted to authorized personnel only. Every access attempt is logged and reviewed. Customer data is isolated at the organization level with tenant-scoped queries enforced at the model layer.

  • Multi-tenant data isolation
  • Role-based access controls
  • Full audit logging of all actions

AI data handling

Candidate data sent to AI providers is covered by data processing agreements. AI-generated outputs are recommendations only - humans make all final hiring decisions. Your candidate data is never used to train third-party models.

  • Data processing agreements with all AI providers
  • No model training on your data
  • Human-in-the-loop for all hiring decisions

Candidate consent at every step

WorkSignal collects explicit consent before any AI interaction. The consent requirements adapt based on the candidate's jurisdiction - Ontario, Illinois, Texas, NYC, and others each have different rules. Our system applies the right ones automatically.

1

Application

AI disclosure shown on the job posting. Candidate agrees to data processing when applying.

2

Scheduling

Jurisdiction-specific consent collected before scheduling. AI screening, recording, and biometric consent where required.

3

Voice screen

AI identifies itself at the start of every call. Recording notice and opt-out option provided verbally.

4

Post-screen

Human reviews all AI assessments. Candidates can request human review if they believe the AI assessment was unfair.

Subprocessors

These are the third-party services that process customer or candidate data on our behalf. Each operates under a data processing agreement.

Provider Purpose Location
DigitalOcean Cloud infrastructure and data storage Toronto, Canada
Stripe Payment processing (PCI DSS compliant) United States
ElevenLabs AI voice screening calls United States
Retell AI AI voice screening calls (backup provider) United States
OpenAI Resume analysis and candidate assessment United States
Anthropic AI-powered candidate evaluation United States
Resend Transactional email delivery United States
Twilio SMS notifications and phone number verification United States
Umami Privacy-focused analytics (no cookies, no PII) Self-hosted, Canada

Data retention

We retain data only as long as needed to provide the service and meet legal obligations.

Account data

Duration of active account + 90 days after closure

Candidate data

Duration of recruiter's active account

Voice recordings & transcripts

Up to 1 year, or until recruiter deletes - whichever is sooner

Compliance records

3 years minimum (Ontario Bill 149 record retention requirement)

Payment & billing

7 years (CRA requirement)

Server logs

Up to 90 days

Compliance roadmap

We are building toward formal certifications alongside our existing compliance infrastructure.

PIPEDA compliance

Canadian federal privacy law. Express consent for sensitive data, implied for less-sensitive. In effect.

Ontario Bill 149 automation

AI disclosure, salary validation, content scanning, 45-day notification tracking. Live and enforced in-product.

Multi-jurisdiction consent engine

Jurisdiction-aware consent collection covering Ontario, Quebec, BC, Illinois, Texas, NYC, California, and GDPR. Live.

SOC 2 Type II

Planned. Formal observation period and audit to follow in 2026-2027.

Documents

Need a Data Processing Agreement (DPA)? Contact us below.

Security contact

For security inquiries, vulnerability reports, DPA requests, or to request our security questionnaire responses, contact us at:

security@worksignal.com