A CIO should choose an applicant tracking system (ATS) that can prove its security controls, not simply claim that it is secure. The key areas to evaluate are independent audits, regulatory compliance, encryption, identity and access controls, secure infrastructure, and data residency.
An ATS stores sensitive candidate information, including resumes, contact details, employment history, assessments, and references. This makes ATS selection a technology, security, and vendor-risk decision, not simply an HR software decision.
Require evidence such as SOC 2 Type 2, which evaluates whether security controls operated effectively over a period rather than only assessing their design at one point in time.
Look for a documented GDPR program and appropriate mechanisms for international data transfers, particularly when candidate information may belong to applicants in different jurisdictions.
The ATS should protect data in transit and maintain firewalls, network restrictions, vulnerability scanning, and other infrastructure security controls.
Evaluate MFA, role-based permissions, administrative access, activity logging, and regular access reviews. Also ask how the vendor controls its own employees' access to customer data.
Review the underlying cloud provider's certifications, backup processes, incident response procedures, vulnerability management, and disaster-recovery capabilities.
Confirm where candidate data is stored and whether the vendor can support region-specific hosting when required by regulatory, contractual, or organizational policies.
ClayHR provides security and reliability controls across these six areas. ClayHR is SOC 2 Type 2 audited and operates a GDPR program based on privacy by design, data minimization, and subject access rights. It is also certified under the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks.
For infrastructure security, ClayHR encrypts traffic in transit, uses IP- and port-based firewall controls, and performs vulnerability scanning with AWS Inspector. The platform supports MFA on iOS and Android, while employee access is governed through approval processes, security training, activity logging, and periodic reviews.
ClayHR is hosted on AWS, with backup servers, continuous database backups, an incident-response process, and a responsible disclosure policy. Region-specific hosting is also available on request.
Yes. ClayHR is SOC 2 Type 2 audited and hosts its data on AWS, which maintains its own SOC 2 certification.
Yes. ClayHR operates a GDPR program and is certified under the EU-U.S., UK, and Swiss-U.S. Data Privacy Frameworks.
Type 1 evaluates control design at a point in time, while Type 2 evaluates whether controls operated effectively over a period. For an ATS handling candidate data, CIOs should prioritize Type 2 or equivalent evidence of operating effectiveness.
For CIOs, the right ATS is one that can demonstrate security through independent assurance, privacy controls, encryption, access governance, resilient infrastructure, and appropriate data residency—not one that simply makes security claims.