Third Party Index

Snapshot 17282

Document
Security page
URL
https://www.crelate.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
604014 bytes
SHA-256 (raw)
e64373b47c253f1a500104b4c17c515503332b1534b9f602af072631620bdd9c
SHA-256 (normalized text)
a27652f083eea4a7ddfe404e0975dee308841610e334f1112438124ad894e8dc

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Crelate AI Recruiting Platform · Measure and improve
Security & performance
ISO 27001 certified security controls and procedures. Enterprise caliber
architecture. And blazing fast performance for your front-line teams,
regardless of your database size.
Legal and policy library
Start free trial
SOC 2 Type II examination, and ISO27001:2022 Certified by A-Lign.
Security
Integrations
API documentation
Platform status
Legal library
Support
Performance and security focused at every level, since day one.
Every Crelate team member has been through security training and background checks. Our product team holds us accountable through stringent code reviews, performance testing, and vulnerability scans. We do this so you can breathe easy.
Built on Microsoft Azure
Multi-tenant environment
100% encrypted at rest
Geo-redundant backups
SOC 2 Type II examination, and ISO27001:2022 Certified by A-Lign. SOC 2 and ISO report access is available as an Enterprise option — see pricing.
Crelate follows industry best practices and runs in Microsoft's Azure cloud.
Azure is SOC 1 and SOC 2 compliant, and we have been a Microsoft Partner working with
the platform since its inception. Azure meets a broad set of international and industry-
specific compliance standards, including ISO 27001, HIPAA, FedRAMP, and SOC 1 and
SOC 2. A complete and up-to-date list of certifications is published on Microsoft Azure’s
compliance page.
Architecture
Multi-tenancy in layers
Crelate exceeds industry best practices at each tier of the application to ensure data is never co-mingled. Preventing unauthorized access to customer data is a top priority, and we take an encrypt-everything approach wherever customer data is handled.
Encryption
Encrypted at rest, end to end
Production storage protected by Azure Encryption at Rest
Backups encrypted from the SQL server with AES-256
100% encrypted at rest
Segmentation
Separated by tenant
SQL Server data segregated by unique tenant ID
Search and reporting built on Elasticsearch
Attachments and resumes in Azure Storage Blob
Each customer gets a unique storage container
A separate, confidential system for your most sensitive searches.
Every layer of our applications and designs is evaluated for performance as
well as security, at any database size.
99%
Uptime
500ms
Requests satisfied in
Live
Status published at
status.crelate.com
View live platform status →
Your data, and who sees it, stays your decision.
Permissions are granted by user, by role, and by record. That is what lets a confidential search stay visible only to the group working it while everyone else uses the same system, and what keeps agents working within the same boundaries as your people.
Advanced user roles and permissions on every plan
Two factor authentication, IP restrictions, and single sign on
Audit log, with field-level auditing on Business Plus and above
EEO, OFCCP and VEVRAA surveys and reports
GDPR compliance management built into the platform
Your records retrievable through the RESTful API or export
Agent access follows the same permission model as the rest of the platform. See how AI works at Crelate →
The documents a security
review usually asks for.
Security policy
How Crelate protects platform and customer data.
Read policy →
Privacy policy
What personal data is collected and how it is used.
Read policy →
Data processing addendum
Processor terms for customers with data protection obligations.
Read the DPA →
GDPR
How Crelate approaches GDPR obligations and data subject requests.
Read more →
Acceptable use policy
What is and is not permitted on the platform.
Read policy →
SOC 2 and ISO reports
Report access is an Enterprise option. Send us your questionnaire and we will work through it.
Contact us →
Questions from security and procurement teams.
Is Crelate SOC 2 and ISO 27001 certified?
Yes, Crelate’s ISMS is certified to ISO/IEC 27001:2022, and Crelate maintains a current SOC 2 Type II report. Both audits are performed by A-Lign.
Where is Crelate hosted?
Crelate is hosted in Microsoft Azure, which is SOC 1 and SOC 2 compliant and meets a broad set of international and industry-specific standards including ISO 27001, HIPAA, and FedRAMP. Crelate is a long-time Microsoft Partner and has worked with Azure since its inception.
Is my data encrypted?
Yes. Crelate takes an encrypt-everything approach. Production storage is protected by Microsoft Azure Encryption at Rest, all backups are encrypted directly from the SQL server using AES-256, and data is 100% encrypted at rest. Backups are geo-redundant.
How is customer data kept separate in a multi-tenant platform?
Crelate implements multi-tenancy in layers at each tier of the application so data is never co-mingled. Database records are segregated by a unique tenant ID, and each customer is provisioned a unique Azure Storage Container for attachments and resumes.
How fast and reliable is Crelate?
Crelate targets 99% uptime and satisfies requests in 500ms, regardless of database size. Live availability and incident history are published at status.crelate.com.
Who at Crelate can access my data?
Every Crelate team member completes security training and background checks, and the product team enforces stringent code reviews, performance testing, and vulnerability scans.
Bring your security questions to the demo. We will answer them there.
Get your demo
Contact us
Scroll to Top