Achilles Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

AchillesHR builds Sam, an AI talent acquisition agent that conducts structured candidate interviews by voice, SMS, and text in over 25 languages. We serve HR and talent acquisition teams at employers filling high volumes of frontline roles in manufacturing, hospitality, energy, and similar industries.

Because Sam handles candidate data on behalf of our customers, security is a product requirement rather than an afterthought. This Trust Center documents our controls, our subprocessors, and our third-party attestations. Use the request button to access our SOC 2 Type 2 report and supporting documentation.

Documents

REPORTSSOC 2 Report

Access Control

Access to the Achilles System is authenticated through Auth0 with role-based permissions. Unique user IDs are enforced for every user; shared and generic accounts are not permitted. Multi-factor authentication is required across production platforms, company email, source control, cloud infrastructure, and third-party systems. Password parameters follow NIST SP 800-63B-4. Access grants and modifications require documented review and CTO approval. User access is reviewed on a quarterly cadence, and an offboarding checklist revokes access on or before an employee or contractor's separation date.

Infrastructure

The Achilles System runs entirely on Amazon Web Services — EC2 on Ubuntu with PostgreSQL — with no company-operated data centers. AWS GuardDuty provides threat detection across accounts and workloads, and CloudWatch monitors production resources, logs, and performance metrics with automated alerting on defined thresholds. Development and production are segregated through separate AWS accounts and environment-specific access controls. EBS volumes and RDS instances are configured with automated daily backups, and restoration is tested through documented RDS snapshot recovery procedures.

Network Security

Cloudflare WAF and AWS security groups restrict unnecessary ports, protocols, and services at the network edge. Administrative access to firewall and security group configuration is limited to authorized personnel. GuardDuty alerts route to management for review and resolution.

Data Security

Production data at rest in AWS RDS and S3 is encrypted using AWS KMS-managed keys. All data transmitted over public networks is encrypted with TLS 1.2 or higher. API keys rotate automatically on a cycle not exceeding 90 days. Cryptographic requirements are documented in our Information Security Policy. Candidate interaction data — voice logs, SMS transcripts, interview records — and HRIS/ATS integration data are stored under these controls and accessible only to authorized users.

App Security

Changes to the Achilles System are formally requested, tracked, tested, and approved before reaching production. Change requests are documented in Linear and linked to the corresponding GitHub pull request, then move through development, peer review, approval, and deployment. Static application security testing runs on major code changes. Developers cannot manually deploy to production; all releases go through the CI/CD pipeline after review and approval.

Product Security

The Achilles System supports role-based access control, so recruiters, hiring managers, and administrators see only the candidate data their role permits. Customer authentication is handled through Auth0 with support for enterprise identity providers. Integrations with customer ATS systems run through the Kombo integration layer over authenticated APIs. Additional detail on enterprise access and integration configuration is available on request.

Endpoint Security

All personnel devices are enrolled in managed device configuration enforcing disk encryption, device protection, automatic updates, firewall, and application download restrictions. Compliance is verified per device and evidence is retained in our compliance platform.

Corporate Security

AchillesHR operates in office with no company-controlled server facilities. Personnel acknowledge our Code of Conduct and information security policies at onboarding and annually. Background checks are performed on all employees and contractors prior to onboarding, and security awareness training is completed at hire and annually thereafter.

Risk Profile

A formal risk assessment is conducted annually by executive management, identifying and ranking risks at the entity and activity level. An independent security risk assessment is performed annually, and an independent vulnerability assessment is performed quarterly against the Achilles System infrastructure. A business continuity and disaster recovery tabletop exercise is conducted at least annually, with documented roles, communication plan, and lessons learned. AchillesHR carries cyber security insurance.

Data Privacy

AchillesHR executes Data Processing Agreements with customers in accordance with applicable data protection requirements. Candidate and customer data is processed solely to deliver contracted recruiting services. Our subprocessor list is available in the SOC 2 report on request and our Privacy Policy is linked on our website.

AI

Sam's conversational and scoring capabilities are powered by large language models from Anthropic and OpenAI, both of which are formally onboarded subprocessors with executed agreements and completed risk evaluations. Candidate interviews follow structured, customer-defined criteria, and scoring results are delivered to the customer's ATS for human review. Hiring decisions remain with the customer. Sam screens and scores against configured criteria; it does not make final hiring determinations.

Legal

Our Terms of Service, Privacy Policy, and standard Data Processing Agreement are available in the documents section. For contract, DPA, or security agreement questions, contact us through the link at the bottom of this page.

Security Grades

We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.

Incident Response

We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.

Risk Management

We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.

Asset Management

We have strict asset management policies in place to ensure that all assets are accounted for and secure.

Training

We provide security awareness training to all employees to ensure that they are aware of security best practices.

Change Management

We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.

Continuous Monitoring

We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.

Built onSafeBase by Drata Logo