Trust, privacy and fairness
Staffing decisions affect people's careers. These protections are built into how FitRank works, not left to configuration.
No automatic assignment
FitRank only recommends. A task is filled only when a person says so, and model changes, threshold changes and feedback suggestions all need an admin.
No protected attributes
Gender, age, religion, caste, ethnicity, nationality, marital status, disability, health, sexual orientation, political views, photos and salaries are never stored, sent to AI or used as signals.
Names stay out of AI
Names and employee codes are never sent to a language model. Codes typed into free text are masked.
Resumes are cleaned first
Names, emails, phone numbers, addresses, links, dates of birth and photos are removed in code before any AI reads a resume.
Answers can't drift into free text
AI returns option letters scored by probability, or strict-schema JSON. Free text is never stored as fact.
Explanations cite facts
Every explanation points to numbered facts. One that cites a fact that doesn't exist is rejected and never shown.
Every company is walled off
Row-level security in the database means a missing filter returns nothing rather than another company's data.
Full audit trail
Sign-ins, user changes, task changes, decisions, thresholds, model switches, imports and outcomes are all audited, and exportable.
Consent and retention
Candidate consent is recorded and candidate files are deleted after a year unless the person is hired.
Fairness you can check
The admin fairness view compares how often qualified people are recommended across locations and practices, using the four-fifths rule and a significance test. Location is only ever used as a hard requirement of the task, never as a scoring signal.
Sign-in and access
Passwords are hashed with argon2. Sessions use short-lived tokens and a secure, HTTP-only refresh cookie. Accounts lock after repeated failed sign-ins, new users must change their temporary password, and every request is checked against the user's role.
Where your data lives
Each company's records are separated by row-level security in the database. The matching model runs inside the deployment, so scoring sends no employee data to an outside AI service. Text that does go to a hosted LLM, such as a task description or a cleaned resume, never includes names or employee codes.
Before you use real data
Every pilot starts with a data-protection and bias review with your HR and legal teams. We'll walk you through what FitRank stores, how long it keeps it, and how to export or delete it.
Questions about security or compliance?
Talk to us before you share any data. We'll answer in writing.