Technology / Security & Privacy
Protection is built in,not bolted on.

Enterprise-grade security and privacy, engineered into the GR8 People platform at every tier — from your data outward.

Compliance · SOC 2 · DPF · GDPR
Resilience · AWS · US+EU · 24/7
Access · RBAC · MFA · SSO
Your data AES-256 · TLS 1.2+
Certifications & Compliance
SOC 2 Type 2 EU-U.S. DPF UK Extension Swiss-U.S. DPF GDPR-aligned TrustArc / TRUSTe verified

Detailed security documentation is shared with qualified prospects at the appropriate stage of the evaluation process. Data Privacy Framework certifications are viewable on the U.S. Department of Commerce DPF list.

Platform security

The controls behind it — safeguarding your data, your candidates, and your uptime, every day.

Data Encryption

Data is encrypted in transit and at rest. We use AES-256 with a unique key per customer for sensitive data, and TLS 1.2+ to protect every connection.

Cloud Infrastructure

Built on AWS with a global footprint and multi-availability-zone redundancy at every tier — across regions in the U.S. and Europe.

Access Control & Authentication

Role-based access control, configurable by you. Multi-factor authentication is enforced on all access points, and every action is logged and monitored.

Single Sign-On

LDAP, SAML 2.0, and OIDC support let you federate sign-on to your own identity provider for seamless, centralized access management.

Data Retention

An active retention policy keeps data aligned to your configuration.

Secure Development

Our secure SDLC pairs static and dynamic code analysis with penetration testing, following OWASP Top 10 and CWE/SANS Top 25 standards.

Availability & Monitoring

Redundancy at every application tier, real-time health monitoring with self-healing, plus managed DDoS protection and a web application firewall keep the platform responsive.

Vulnerability & Incident Response

Independent third-party vulnerability assessments run weekly, backed by endpoint threat detection and a documented, rehearsed incident response plan.

Your data, your control

You decide how candidate and employee data is used. We only ever process it on your instructions.

Controller & Processor

You are the data controller; GR8 People is the processor. You retain full control of your data, roles, workflows, consent settings, and retention rules.

Global Privacy Frameworks

Certified under the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. DPF, with third-party verification by TrustArc (formerly TRUSTe).

GDPR-Aligned Practices

Privacy impact assessments, records of processing activities, employee privacy training, and configurable compliance features built into the platform.

Your Rights & Choices

Access, correct, or delete your information and opt out of marketing at any time. Reach our privacy team at privacy@gr8people.com.

Your data stays yours.