Trust

Security at Crooter.

The controls, processes and design decisions that keep your candidates, clients and conversations safe.

Last updated · 26 June 2026

Our approach

Crooter is built for recruitment teams that handle sensitive candidate, client and communication data every day. Security is treated as a product requirement, not a checklist — controls are implemented in code, reviewed regularly and monitored in production.

Encryption

All traffic to Crooter is encrypted in transit using TLS 1.2 or higher. Customer data, OAuth tokens and backups are encrypted at rest using AES-256. Database connections between application services and storage are encrypted end-to-end.

Authentication

Crooter supports password-based sign-in and federated sign-in with Google and Microsoft. Passwords are salted and hashed using industry-standard algorithms. Sessions are bound to short-lived tokens that rotate automatically.

OAuth integrations

Integrations with Gmail, Outlook, WhatsApp Business and other providers use standard OAuth 2.0 / OpenID Connect flows. Users grant explicit consent before any data is exchanged, Crooter requests only the scopes a feature requires, and tokens are stored encrypted. Disconnecting an integration revokes Crooter’s access and removes stored tokens.

Access controls

Production access is restricted to a small, named group of engineers. Access is granted on a least-privilege basis, requires SSO with multi-factor authentication and is logged for audit. Access reviews are performed regularly.

Role-based permissions

Inside a Customer workspace, every action is gated by role-based permissions. Administrators control which users can view candidates, edit roles, send communications, manage billing and invite teammates. Permissions are enforced in the database with row-level security so a missing UI check cannot leak data.

Data protection

Personal data is processed in accordance with the UK and EU GDPR. Customers retain ownership of their data, can export it at any time and can request deletion in line with our retention schedule.

Infrastructure

Crooter runs on hardened cloud infrastructure with isolated environments for development, staging and production. Backups are encrypted, geographically replicated and tested. Application dependencies are scanned automatically for known vulnerabilities and patched on a defined cadence.

Monitoring & incident response

Production systems are monitored continuously for availability, errors and anomalous behaviour. We maintain a documented incident response process and will notify affected Customers without undue delay where a confirmed security incident materially affects their data.

Responsible disclosure

If you believe you have discovered a security vulnerability in Crooter, please report it to security@crooter.co.uk. We commit to acknowledging valid reports promptly, investigating in good faith and not pursuing legal action against researchers who follow this process.

Compliance roadmap

Crooter is actively working towards SOC 2 Type II readiness, with mappings to ISO 27001 controls. Customers with specific compliance or due-diligence questions can request our current security pack via security@crooter.co.uk.