Third Party Index

Snapshot 35823

Document
Subprocessor list
URL
https://trust.ashbyhq.com/?itemUid=e3fae2ca-94a9-416b-b577-5c90e382df57
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
467385 bytes
SHA-256 (raw)
5615d81df009ee48de968872c2dde7198547a823eb538e7625833127ef0a40cb
SHA-256 (normalized text)
4785f800b01a21388bfc9d0f82b9d1686e91545e240310a72e2328d3eb9c32f7

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Start your security review
View & download sensitive information
Overview
Recruiting and HR data is critical to your business and we take the security of customer data extremely seriously. Please use this Trust Center to learn more about security posture and request access to more security information.
Compliance
SOC 2 Type 2
EU-US DPF
Swiss-US DPF
UK Extension to EU-US DPF
SOC 1 Type 2
Documents
DOCUMENTS2026-07-23: Trusted Platform Abuse
REPORTSNetwork and System Architecture Diagram
REPORTSPentest Report
REPORTSSOC 1 Report
REPORTSSOC 2 Report 2024
REPORTSSOC 2 Report 2026
REPORTSSOC2 Type Report 2025
REPORTSVulnerability Assessment Report
COMPLIANCESOC 1 Type 2
COMPLIANCESOC 2 Type 2
SELF-ASSESSMENTSCAIQ
SELF-ASSESSMENTSOther Self-Assessments
Risk Profile
Critical DependenceNo
Third Party DependenceYes
HostingMajor Cloud Provider
Product Security
Data Security
Fraudulent Candidate Management
Role-Based Access Control
View more
AI
Responsible AI Statement
AI Interviewer - Bias Audit Report
AI Criteria Evaluation - Bias Audit Report
View more
Reports
Network and System Architecture Diagram
SOC 2 Report 2026
Other Reports
View more
Self-Assessments
CAIQ
Other Self-Assessments
VSAQ - All In One Product
Policies
Acceptable Use Policy
Access Control Policy
Asset Authorization and Monitoring Policy
View more
Data Security
Data Backups
Data Erasure
Encryption-at-rest
View more
App Security
Application Penetration Testing
Secure Development Training
Software Development Lifecycle
View more
Legal
Subprocessors
Cyber Insurance
Data Processing Agreement
View more
Data Privacy
Ashby Data Transfer Impact Assessment - FAQ
Data Breach Notifications
Employee Privacy Training
Access Control
Internal Single-Sign-On (SSO)
Least Privilege
Password Manager
Infrastructure
Status Monitoring
Amazon Web Services
BC/DR
Endpoint Security
Anti-Malware
Disk Encryption
Endpoint Detection & Response
View more
Network Security
We protect our corporate network against external & internal threats.
Corporate Security
Asset Management Practices
Email Protection
Employee Training
View more
Security Grades
Qualys SSL Labs
A+
Incident Response
We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.
Risk Management
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
Asset Management
Asset Classification
IT Asset Management (ITAM) Program
Secure Asset Disposal
BC/DR
Business Continuity Plan (BCP)
Contingency Plan Testing/Lessons Learned
Data Backup/Backup Protection
View more
Training
Security Awareness Training
Social Engineering Training
Change Management
We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.
Physical & Environment
We have physical and environmental controls in place to ensure that our data centers are secure and reliable.
Continuous Monitoring
We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.
Knowledge Base (FAQ)
Can data retention be customized?
Where is the AI model hosted?
Where is Ashby being hosted?
Can you provide SOC2 Report, Pentest, etc.?
Do we have access to logs of prompts submitted by our employees? Does it show when it ingest our data?
View more
Ashby is reviewed and trusted by
Lemonade
Sequoia
Reddit
Ramp
Deel
Retool
Vanta
Notion
Trust Center Updates
Subprocessor Updates
Subprocessors
Ashby is adding the following subprocessor:
Braintrust
Purpose: AI Observability & Evaluation
Please see here for a full list and details: https://trust.ashbyhq.com/?itemUid=e3fae2ca-94a9-416b-b577-5c90e382df57&source=click
The Ashby Security Team
Ashby is adding the following subprocessors:
Polytomic
Purpose: ETL
Plain
Purpose: Customer Support
Seon
Purpose: Optional Candidate Fraud Signal Functionality
Assembly AI
Purpose: Optional AI Notetaker Add-on
Recall AI
Purpose: Optional AI Notetaker Add-on
Please see here for a full list and details: https://trust.ashbyhq.com/?itemUid=e3fae2ca-94a9-416b-b577-5c90e382df57&source=click
The Ashby Security Team
Terms
General
Ashby has updated our Terms for AI Features to support new AI features.
Please follow the link above to review the updates in their entirety. For clarity, we have made the following updates:
Confirmed and clarified that Ashby Customers retain ownership for all outputs from AI Tools.
Introduced terms that will apply to Ashby’s AI Notetaker that is being released this Thursday 9/25.
Questions? Please reach out to the Ashby Support Team at [email protected]
Ashby
New SOC1/SOC2 reports added
General
SOC1 and SOC2 Type II reports for the Audit period 08/01/2024 - 11/30/2024 have been added. Going forward, our Audit period is going to be 12/01 - 11/30.