Security and trust

Clear answers are better than broad security promises

Recruitment data can be sensitive. Our approach is to document what we can support today, keep product claims tied to evidence, and answer additional security questions directly.

This page describes our current public trust position. It is not a certification, security audit, or substitute for your own legal and procurement review.

What you can expect from us

A named operator

GoJobee is operated by SmartDev Sp. z o.o. in Bielsko-Biała, Poland. Our legal and privacy pages identify the service provider and data controller details.

Encrypted website connections

Our published privacy policy states that we use SSL/TLS to protect connections. We do not publish unverified claims about specific cipher versions or encryption standards.

Claims that follow product readiness

Capabilities such as SSO, customer audit logs, custom compliance terms, API access, and formal SLAs are not presented here as generally available without individual confirmation.

A direct route for questions

Security, privacy, procurement, and vulnerability reports can be sent to [email protected] for review by the team.

A shared responsibility

Trust in a hiring system depends on both the product and how each organization uses it.

  • Customers decide which candidate information is appropriate to collect and who should have access to it.
  • Teams remain responsible for lawful hiring practices, retention choices, and responding to candidate rights requests.
  • GoJobee provides product controls and documentation, but using an ATS does not automatically make a hiring process compliant.

AI assists. People decide.

GoJobee positions AI as support for reviewing information and preparing hiring work. AI output should be checked in context, and responsibility for evaluating candidates and making employment decisions remains with people.

  • Treat generated summaries and signals as supporting material, not final judgment.
  • Review source information before acting on an AI-assisted result.
  • Do not use AI output as the sole basis for an employment decision.

What we do not imply

We do not claim a security certification that is not published and verifiable.

We do not describe roadmap capabilities as active product controls.

We do not promise that one configuration fits every regulatory or procurement requirement.

We do not publish a response-time guarantee unless it is part of an agreed service arrangement.

Need a security or privacy review?

Tell us what your team needs to verify. We will answer from the information available today and clearly identify anything that requires separate confirmation.