Key takeaway: Every serious AI recruiting vendor claims SOC 2, so SOC 2 is not a differentiator. The four questions that actually separate vendors are whether your candidate data trains their AI models, which ISO standards they hold, whether SSO/SAML is available without an enterprise upgrade, and whether their pricing model quietly pushes your team toward shared logins. Of the seven vendors compared below, only two state in public that they do not use customer data to train their AI models (Juicebox and SeekOut), three publish ISO 27001 or newer AI-management certifications (Gem, Greenhouse, hireEZ), and only Noon removes the per-seat pricing incentive that leads recruiting teams to share credentials in the first place.

Security review is now the gate that AI sourcing purchases die at, not the pricing conversation. The cost side of the argument keeps getting worse, and it is now specifically an AI problem. IBM's 2026 Cost of a Data Breach Report, based on breaches at 602 organizations between March 2025 and February 2026, found that one in four malicious breaches were AI-enabled, a 56% increase over the prior year, and that those breaches cost an average of USD 6 million against a global breach average of USD 4.99 million (IBM newsroom, 29 July 2026). More than 20% of organizations reported a breach that targeted AI models or applications, with compromised APIs, applications or plug-ins and cloud misconfigurations affecting AI workloads tied as the leading causes at 27% each. The same study found only 37% of breached organizations encrypt sensitive data both at rest and in transit, which is worth remembering the next time a vendor page lists encryption as a headline control.

Recruiting is a bad place to be casual about this, because a sourcing tool holds exactly the data attackers want: names, employers, personal email addresses, phone numbers, and in some cases compensation notes, for people who have not applied for a job and have no relationship with your company.

In evaluation calls, the security question is not asked once. The three most frequent compliance themes we hear are "what are the security, data privacy, and intellectual property implications of using the platform", "what are the platform's data sources for candidate profiles and contact information", and "what security and compliance documentation is available for review", and the single most common concrete objection is whether an AI sourcing tool violates another platform's terms of service. That order matters: buyers care about data provenance and paperwork before they care about certifications.

What did each vendor actually publish?

The table below records only what each vendor states on its own public security or trust page, read on 21 August 2026. "Not stated" means the claim is absent from that public page, not that the vendor lacks the control. Every cell is checkable from the linked source.

Vendor SOC 2 Other certifications GDPR SSO / SAML Customer data used to train AI models? Public source
Noon Type II Not stated Compliant Yes Not stated noon.ai/enterprise
Juicebox Type II (report on request) AI bias audit (NYC Local Law 144), penetration test report on request Compliant Not stated No, stated explicitly for in-house and third-party models trust.juicebox.ai
SeekOut Type 2, certified as of 8 June 2023 ISO/IEC 42001:2023, ISO/IEC 23894:2023 Compliant (plus CCPA) Yes, SAML 2.0 No, "does not use any client data to train our AI models" seekout.com/security
hireEZ Type 2 ISO 27001, TrustArc data privacy framework, OFCCP Compliant Not stated Not stated hireez.com/security-compliance
Gem SOC 1, SOC 2, SOC 3 (via AWS infrastructure) ISO 27001, 27017, 27018, PCI (infrastructure) DPA offered Yes Not stated gem.com/security
Greenhouse Type 2 ISO 27001:2022, ISO 27701:2019, ISO 42001:2023; bug bounty GDPR, CCPA/CPRA Yes Not stated greenhouse.com/security
Workable Type II (on request), SOC 3 Annual partner security assessments GDPR, CCPA Yes Not stated workable.com/security

Three things stand out.

SOC 2 is table stakes, and it is often infrastructure inheritance. Every vendor here claims SOC 2 in some form. Some of those claims describe the vendor's own audited controls, and some describe the certifications of the cloud provider underneath. Gem's security page, for example, lists ISO 27001, 27017, 27018, SOC 1, SOC 2 and SOC 3 in the context of its AWS infrastructure. Read the sentence around the badge, not the badge.

The AI-training question is where the real variance is. Only Juicebox and SeekOut answer it in public. Juicebox states it does not use customer data to train its AI models, covering both in-house models and third-party ones, and separately discloses its subprocessors and an NYC Local Law 144 bias audit. SeekOut states plainly that it "does not use any client data to train our AI models" and holds ISO/IEC 42001:2023, the AI management systems standard. For every other vendor in the table, including Noon, the answer is not on the public page and belongs in your security questionnaire.

Certification depth beats certification count. Greenhouse (ISO 27001:2022, 27701:2019, 42001:2023) and hireEZ (ISO 27001, AES-256 at rest, annual third-party penetration testing) publish the most detailed control descriptions. SeekOut publishes the most AI-specific ones. Detail is a reasonable proxy for maturity: a vendor that documents key management and pen-test cadence has usually been through enterprise reviews before.

Which security questions should be in your RFP?

Use these ten. They map onto what buyers in our own evaluation calls ask most often, and the first four are the ones that most frequently have no public answer.

  1. Do you use our data, including candidate profiles and message content, to train or fine-tune models? For in-house and third-party models separately.
  2. Where does candidate profile and contact data come from, and what is your legal basis for processing it?
  3. Which subprocessors touch our data, and where are they hosted?
  4. What is the data retention and deletion process, including deletion on contract termination?
  5. Is SOC 2 Type II your own audit, and will you share the report under NDA?
  6. Is SSO/SAML included, or is it gated behind a higher tier?
  7. Do you run annual third-party penetration tests, and will you share a summary?
  8. Have you run a bias audit, and can you provide the summary required by NYC Local Law 144?
  9. What is your incident notification window in the DPA?
  10. Which of your AI features make or materially assist an employment decision, as opposed to ranking or drafting?

Question 2 deserves emphasis, because a persistent misconception is that AI sourcing tools only pull candidates from LinkedIn. Most do not, and the ones that scrape a single network are precisely the ones exposed to the terms-of-service objection buyers raise most often. Ask for the actual source list.

What regulation applies in 2026?

Two obligations are live now, and one large one is not yet.

NYC Local Law 144 is enforced today. Employers and employment agencies may not use an automated employment decision tool unless it has had a bias audit within the previous year, a summary of the audit results is publicly posted, and candidates receive notice at least 10 business days before use. DCWP has enforced it since 5 July 2023 (NYC Department of Consumer and Worker Protection). The obligation sits with the employer, not the vendor, so "our vendor handles it" is not a defense. Ask for the audit summary.

EU AI Act enforcement began on 2 August 2026, covering prohibited practices, transparency obligations for certain AI systems, and general-purpose AI model rules (European Commission AI Act Service Desk). If your sourcing tool generates candidate-facing content, the Article 50 transparency obligations are the ones to read first.

The high-risk regime for employment AI is not in force yet. Under the revised timeline, Annex III high-risk rules, which include employment and worker management, apply from 2 December 2027, and high-risk systems embedded in regulated products from 2 August 2028. That is your window to get vendor documentation, logging, and human-oversight design in order rather than a reason to defer the question.

GDPR remains the baseline for any EU candidate data, which is why "GDPR compliant" plus a signed DPA is the minimum bar in the table above rather than a selling point.

Does per-seat pricing create a security problem?

This is the part of vendor security that no trust center covers, and it is worth more than most control matrices.

When a sourcing tool is priced per seat, teams ration seats. The hiring manager who wants to review a shortlist gets someone else's login, the coordinator runs searches from the sourcer's account, and the audit trail stops meaning anything. Credential sharing then defeats the SSO, role-based access control, and per-user logging that the vendor's security page advertises. It is also invisible to a security questionnaire, because it is a procurement artifact rather than a product defect.

Two of the most common frictions we hear in evaluation calls sit next to this: hesitancy about granting broad email access to an AI tool, and IT departments blocking new recruiting tools outright, especially at the email-integration step. Both go better when access can be provisioned properly for every person who needs it, with SSO, instead of being economized.

At Noon, this is a pricing decision with a security consequence. Noon is one plan with unlimited seats, unlimited sourcing, unlimited contacts, and unlimited agents, with no per-seat fees (Noon pricing). There is no reason to share a login, so every action stays attributable to a real person. Alongside that, Noon is SOC 2 Type II compliant, GDPR compliant, supports SSO and SAML, offers custom contracts and data residency options for enterprise buyers, and connects to 20+ ATS providers through a unified integration layer, which keeps candidate records flowing into your system of record instead of accumulating in a second silo. For a deeper look at how the autonomous sourcing side works, see the AI Sourcer product page and our guide to enterprise AI recruiting software.

How should a small team run this review?

You do not need a security team to do this well. You need a short, fixed process.

  1. Pull the public page first. Read the vendor's own security or trust page and record what it does and does not say. Half of the answers in the table above are absent from public pages, and knowing which half saves a round trip.
  2. Send the ten questions above as one document. Vendors answer a structured questionnaire faster than a thread.
  3. Request the SOC 2 Type II report under NDA and read the exceptions section. The exceptions, not the badge, tell you how the vendor operates.
  4. Confirm SSO is in your tier, in writing. SSO gated behind an enterprise upgrade is a common surprise.
  5. Check the AI-decision boundary. Tools that rank and draft are treated differently from tools that decide. Write down which of your workflows involve a human making the actual decision.
  6. Bring IT in before the pilot, not after. Email integration is the step most likely to be blocked, and it is much easier to clear as a planned review item.

For the certification background, our SOC 2 recruiting software guide covers the five trust services criteria and what a Type II report actually contains. If you are still shortlisting, the best AI recruiting software roundup and our AI sourcing tools comparison cover the functional side, and the head-to-head pages Noon vs Juicebox and Noon vs SeekOut compare two of the vendors in the table above in full.

FAQ

Is SOC 2 Type II enough to approve an AI recruiting tool? No. SOC 2 Type II tells you a vendor's controls were tested over a period of time, which is necessary but not specific to AI risk. It says nothing about whether your candidate data trains the vendor's models, where profile data comes from, or whether the tool participates in employment decisions. Pair it with the AI-specific questions above.

Which AI recruiting vendors say they do not train on customer data? Of the seven compared here, Juicebox and SeekOut state this publicly. Juicebox's trust center says customer data is not used to train its AI models, for in-house and third-party models, and SeekOut's security page states it does not use client data to train its AI models. The others do not address it publicly, so ask directly and get the answer in the contract rather than in an email.

Does ISO 42001 matter for recruiting software? It is becoming a useful signal. ISO/IEC 42001:2023 covers AI management systems, meaning governance of how AI is built and monitored, rather than general information security. SeekOut and Greenhouse both publish it. It is not a legal requirement, but a vendor that has been audited against it will usually have the documentation your legal team asks for.

Who is responsible for the NYC bias audit, the employer or the vendor? The employer or employment agency using the tool. Local Law 144 requires a bias audit within the previous year, a public summary of the results, and notice to candidates at least 10 business days before use. Vendors can supply the audit, but the legal obligation to publish and notify is yours.

Is Noon SOC 2 and GDPR compliant? Yes. Noon is SOC 2 Type II compliant and GDPR compliant, supports SSO and SAML, and offers dedicated support, custom contracts and invoicing, and data residency options for enterprise customers. Because Noon is a single plan with unlimited seats, security teams can provision access for everyone who needs it rather than rationing logins. Book a demo if you want the security documentation walked through with your team.

What is the single most overlooked security question in a recruiting tool review? Data provenance. Buyers routinely ask where candidate profiles and contact details come from, and it is the question with the widest quality range between vendors. A tool that sources across the public web under documented policies is a different risk profile from one that depends on scraping a single professional network, which is also the source of the terms-of-service concern that comes up most often in evaluation calls.