Security & infrastructure

Your data, hosted in Europe, on infrastructure under constant monitoring.

Clarentia clearly distinguishes its own application security measures from the certifications that belong to its hosting provider, AWS — for full transparency, no shortcuts.

At a glance

Hosting
AWS eu-west-3 · Paris
In transit
HTTPS / TLS v1.2+
At rest
AWS KMS encryption (EBS)
Backups
Daily · 5 d
Clarentia access
RBAC · AWS SSM · MFA

Hosting in the European Union

Recruitment data is hosted on Amazon Web Services infrastructure, in France. Production, staging and development environments are kept separate.

Region
AWS Europe (Paris) — eu-west-3
Subprocessors

Encryption in transit and at rest

Traffic between users and Clarentia is encrypted via HTTPS/TLS. Stored data is encrypted using the AWS infrastructure's encryption mechanisms.

In transit
HTTPS/TLS v1.2 & v1.3 TLS 1.2+ enforced
At rest
AWS KMS AES-256 EBS encrypted

Application access control

Access to application features and data follows a role-based model (RBAC). Each client company manages its own users and permissions. Each client company's data is further logically isolated by client identifier, ensuring no client can access another's data.

Application roles
Admin · Recruiter
Internal Clarentia access
MFA required
Multi-tenant isolation
Logical segregation by client ID confirmed

Backups and continuity

Production instances are backed up daily via Amazon Data Lifecycle Manager, following a rolling retention policy.

Frequency
Daily (EBS) · 3 dumps / day (SQL)
Retention
5 days (EBS) / last 30 SQL dumps
Availability (SLA)
99.5% contractual commitment

Vulnerability management

Vulnerability scans are performed on a recurring basis to identify and fix potential weaknesses. Penetration tests are now conducted on a quarterly basis to assess the application's security.

Scans
~ every 2 months
Pentest
Quarterly confirmed

GDPR & AI Act compliance

Clarentia applies GDPR requirements to the processing of recruitment data (designated DPO, data processing agreement, published subprocessors with their transfer safeguards). AI-assisted recruitment also falls under the "high-risk" use cases of the European AI Act (Annex III, employment): the associated technical obligations have been postponed, but the transparency requirements toward candidates — already applicable since August 2026 — are implemented in the product: every candidate is informed when interacting with an AI system.

GDPR
DPO · DPA · published subprocessors
AI Act — high-risk
Postponed to Dec 2, 2027
AI Act — transparency (Art. 50)
Applicable since 08/2026 implemented
Human oversight
Systematic recruiter review

Infrastructure compliance

The AWS infrastructure underlying Clarentia benefits from the ISO 27001, SOC 1/2/3 and PCI DSS compliance programs. These are AWS's certifications, our hosting provider, covering its infrastructure — their scope has been verified to cover the eu-west-3 (Paris) region via AWS Artifact.

AWS programs
ISO 27001 · SOC 1/2/3 · PCI DSS Verified for eu-west-3 (Paris) via AWS Artifact
Security and Data Hosting | Clarentia