← All resources

Trust centre · MinMaxHR

MinMaxHR security and data handling: the procurement answers, stated precisely

MinMaxHR stores and processes candidate data in Mumbai, India (Google Cloud asia-south1), isolates every workspace at the database level, encrypts data in transit and at rest, scans uploads for malware by default, and time-bounds support access to a maximum of 24 hours with separate logging. CandidRanker acts as a data processor for workspace data.

This page is written for the people who actually read it: security reviewers, IT, legal and procurement. It states specifics rather than adjectives, and it says plainly where a control stops.

MinMaxHR implements SOC 2-aligned controls across access management, encryption, logging and data handling, with independent certification on the roadmap. Every control described on this page is testable on the free plan before any commercial conversation, verification beats assertion.

Data residency

Customer and candidate data is stored and processed in Mumbai, India, on Google Cloud region asia-south1. This is the first question most Indian procurement teams ask and the first one many vendors answer vaguely.

MinMaxHR states residency as a fact about where the data sits. It does not present that as a blanket legal conclusion about every localisation or cross-border transfer requirement your organisation may be subject to. That assessment depends on your deployment, your sector and your contracts, and should be made with your own counsel.

Tenant isolation and access control

  • Every API request is checked against workspace membership before any data is returned.
  • Database-level row security operates underneath that check as defence in depth, so an application-layer mistake does not become a data leak.
  • API keys and AI assistant tokens are bound to a single workspace and carry only the scopes granted at issue.
  • Roles scope what recruiters, hiring managers and administrators can see to the work in front of them.
  • For staffing agencies this is the operative control: one isolated workspace per client, with nothing crossing the boundary.

Encryption and credential handling

Data is encrypted in transit with TLS and encrypted at rest. API keys are stored as SHA-256 hashes rather than recoverable secrets, which means MinMaxHR cannot show you an existing key. A lost key is reissued, not retrieved. That is the correct behaviour, and it is worth knowing before you need it.

Upload hygiene

Every uploaded file is malware scanned by default. A workspace setting can disable scanning; files uploaded while it is disabled are marked unscanned so the state is visible rather than assumed. Infected or unscannable files are quarantined and flagged.

The precision matters. An earlier version of MinMaxHR's own buyer material said every file is scanned, full stop. That was an overstatement, it was corrected, and the corrected wording is what appears here and everywhere else on this site.

Support access

MinMaxHR support staff do not hold standing access to customer workspaces. Access is explicit, granted for a defined purpose, time-bounded to a maximum of 24 hours, read-only unless you grant more, and logged separately from ordinary workspace activity so you can review it independently.

Deletion, retention and data subject rights

Deletion removes extracted data, rankings and stored files, including quarantined copies. Retention is a recorded property of the workspace rather than an informal habit.

Deletion is available today. One-click data-subject export is on the roadmap; if a subject-access workflow is a procurement requirement for you, raise it early so we can confirm where it stands for your timeline.

Governance controls a reviewer can test

  • No candidate is ever auto-rejected: shortlist, select and reject are human actions requiring a written reason.
  • Every decision is attributable to a named recruiter, with the reason stored alongside it.
  • Changes to scoring weights, ranking filters, skills, aliases and terminology are recorded with the person, the time, the before and after values, and a reason.
  • Decision history, configuration changes, document edits and re-parses, membership changes and support access are all preserved in audit history.
  • Scoring is deterministic, so the ranking reconstructed in an audit is the ranking the system actually produced.

These are testable on the MinMaxHR free plan before any commercial conversation. That is deliberate: a control you have verified yourself is worth more than a control we have asserted.

Regulatory position

CandidRanker acts as a data processor for workspace data. MinMaxHR's design is aligned with India's DPDP Act and with GDPR expectations around automated decisions, principally by ensuring decisions are not solely automated. Legal conclusions for your specific deployment, sector and transfer requirements should be reviewed by your own counsel; this page is product and control documentation, not legal advice.

Frequently asked questions

Where does MinMaxHR store candidate data?
In Mumbai, India, on Google Cloud region asia-south1, in tenant-isolated workspaces with TLS in transit and encryption at rest.
Is MinMaxHR SOC 2 certified?
MinMaxHR implements SOC 2-aligned controls across access management, encryption, logging and data handling, with independent certification on the roadmap. Procurement teams can verify every control described here directly on the free plan rather than taking it on trust. If a completed SOC 2 report is a prerequisite at signing for your organisation, tell us early and we will confirm where certification stands against your timeline.
How are staffing agency clients kept separate in CandidRanker?
Each client gets a fully isolated workspace. API requests are checked against workspace membership and database-level row security operates underneath as defence in depth. API keys and assistant tokens are workspace-bound.
Are uploaded resumes scanned for malware?
Yes, by default. A workspace setting can disable scanning, and files uploaded while it is disabled are marked unscanned so the state is visible. Infected or unscannable files are quarantined and flagged.
Can MinMaxHR staff access our candidate data?
Not by default. Support access is explicit, time-bounded to a maximum of 24 hours, read-only unless you grant more, and logged separately so you can review it.
Can we delete candidate data on request?
Yes. Deletion removes extracted data, rankings and stored files including quarantined copies. One-click data-subject export is on the roadmap.
Is CandidRanker a data controller or a data processor?
CandidRanker acts as a data processor for workspace data. Your organisation remains the Data Fiduciary or controller for the candidate data you collect.
What can a security reviewer verify without a contract?
Most of it. The MinMaxHR free plan lets a reviewer test deterministic scoring, per-dimension explainability, the absence of auto-rejection, named-recruiter decision records, and the audit trail on real data before any commercial commitment.

Related resources