LogoNoon

Last updated 24 August 2026

Security and trust

Recruiting data is candidate data, so an AI recruiter has to clear the same review as any other system touching it. This is what Noon holds, how candidate data moves, and exactly what to put in front of your security team.

What Noon holds

Only what is audited, nothing implied.

SOC 2 Type II compliant
GDPR compliant
SSO and SAML authentication
Data residency options available
Dedicated enterprise support

01

Certifications and compliance

Noon is SOC 2 Type II compliant, which means our security controls have been independently audited over a period of time rather than at a single point. Noon is also GDPR compliant and processes candidate and user data in line with GDPR requirements. We publish only what we hold: if a framework is not named on this page, we do not claim it. When a security questionnaire asks for a certification we do not hold, your account team will tell you that directly instead of routing you through a sales cycle.

02

Access and identity

Noon supports single sign-on including SAML, so your team authenticates through the identity provider you already govern and offboarding a recruiter in your directory removes their Noon access with it. Enterprise agreements can include data residency options and custom contracting terms. If your review requires specifics beyond what is listed here, ask your account team rather than inferring them from this page.

03

How candidate data flows

Noon sources candidates across the open web, evaluates them against the criteria your team defines, and runs outreach and scheduling on your behalf. Activity syncs back to your applicant tracking system through an integration layer covering 20+ providers, so your ATS stays the system of record and Noon does not become a second, unreviewed candidate database sitting outside it. Connecting email or an ATS is an explicit, admin-authorized step, not a default.

04

What your security reviewer should ask for

Bring us the questionnaire early. The fastest reviews we see start with three requests: the SOC 2 Type II report under NDA, the subprocessor and data-flow description for the integrations you plan to enable, and confirmation of SSO or SAML configuration for your identity provider. Your account team coordinates all three, and a dedicated contact stays with enterprise accounts after the review closes.

Security questions we get asked
Is Noon SOC 2 compliant?

Yes. Noon is SOC 2 Type II compliant, meaning the controls have been independently audited over time rather than assessed at a single moment. Enterprise buyers can request the report through their account team as part of a security review.

Is Noon GDPR compliant?

Yes. Noon is GDPR compliant and processes candidate and user data in accordance with GDPR requirements. Data protection details for individuals are covered in the Noon privacy policy and privacy center.

Does Noon support SSO and SAML for team logins?

Yes. Noon supports single sign-on including SAML, so access is governed by your identity provider rather than by individual passwords. For requirements beyond SSO and SAML, ask your account team what is available on your contract rather than assuming.

What security and compliance documentation is available for review?

Noon's SOC 2 Type II report is available to enterprise buyers under NDA, alongside a description of how candidate data flows between Noon, your email, and your applicant tracking system. Request both through your account team at the start of the review, not the end.

What is the process for IT security approval to integrate with our work systems?

Integrations are admin-authorized. An administrator connects the applicant tracking system or mailbox explicitly, and Noon syncs sourcing, outreach, and scheduling activity back to that system of record. Share the integration list you intend to enable with your account team so the review covers exactly those connections.

Which security certifications does Noon not claim?

Noon publishes SOC 2 Type II and GDPR compliance, SSO and SAML support, dedicated enterprise support, and custom contracting with data residency options. Anything not listed on this page is not claimed. If your policy requires a framework beyond these, tell your account team before the technical evaluation so nobody wastes a cycle.

Does Noon replace our applicant tracking system?

No. Noon integrates with 20+ applicant tracking systems and syncs activity back to the one you already use, so your existing system stays the record of candidate data and the review scope stays narrow.

How is pricing structured for enterprise security reviews?

Noon sells one plan with unlimited sourcing, contacts, agents, and seats, so a security review does not force a plan change and adding reviewers or admins does not change your contract shape. Pricing is quote-based; the pricing page is the official answer.

Related pages
Starting a security review?

Book a demo and your account team will send the documentation your reviewers need and confirm what is available on your contract.