Security

Security & Compliance

Last updated: October 8, 2025

Trust is the foundation of any recruiting platform. This page summarizes how GENIUS FOR PEOPLE, S.L. (Mainder) protects your information and the candidate data you manage in Mainder.

Infrastructure

Mainder runs on AWS with a multi-AZ architecture. Production environments are isolated from development and staging. We apply system hardening, automated security patching and continuous infrastructure monitoring.

Data encryption

All data in transit uses TLS 1.3. Data at rest is encrypted with AES-256. Encryption keys are managed via AWS KMS with periodic rotation.

Access controls

We apply least-privilege access on internal systems and within the platform. Customers configure granular roles and permissions. Mainder employee access to production data requires approval, justification and is logged in audit trails.

Certifications and compliance

We operate under GDPR and are ISO 27001:2022 certified. SOC 2 Type II certification is in progress. We conduct impact assessments for high-risk AI features and document controls aligned with the EU AI Act.

European data processing

All infrastructure and AI processing runs exclusively within the European Union (Ireland and London), ensuring data sovereignty and GDPR compliance for our European clients.

No training on your data

Your data is never used to train AI models. This is guaranteed contractually and enforced technically at every step of the process.

Anti-prompt manipulation defense

Backend controls prevent prompt injection, manipulation and unauthorized filtering. AI outputs are never sent outside the platform automatically.

AI monitoring and traceability

Every AI input and output is logged. We continuously evaluate responses and version prompts to keep interactions controlled and secure.

Human in the loop

AI at Mainder is advisory, not executive. Every critical HR decision requires mandatory human validation, in line with responsible AI principles.

Transparent and traceable results

Every AI-generated response comes with transparent reasoning, verifiable source references and documented scoring, so results are fully traceable.

Vulnerability management

We run automated dependency scanning, security-focused code review and periodic third-party penetration tests.

Incident response

We maintain a documented incident response plan with target times for detection, containment and notification. If a breach affects personal data, we will notify customers and authorities under GDPR within legal timeframes.

Data protection and retention

We perform continuous backups with point-in-time recovery. Data is securely deleted at the end of configured retention or after service cancellation, except where legal retention applies.

Trusted subprocessors

We only work with subprocessors assessed under our third-party risk program, including AWS and essential infrastructure providers under GDPR Art. 28 agreements.

Report a vulnerability

If you discover a security vulnerability, please report it responsibly to security@mainder.ai. We respond within 72 business hours and appreciate coordinated disclosure.