Enterprise-grade from the database up.
Your data stays in its own walls. Every AI output stays a recommendation to a human. And the artifacts your auditors ask for are already in the product, built to pass a serious security review.
Three commitments we hold structurally.
A human stays on the decision
Every AI output is a recommendation displayed to a person: read, weighed, acted on at their discretion. No auto-reject, no auto-advance, no auto-hire anywhere in the product. It’s an architectural constraint, not a setting that could flip off by accident.
- 02
Your data is yours
Never sold. Never pooled with another customer’s. Never used to train a shared or cross-customer model. The calibration that tunes CertAIn to your team lives in your account, on your data, isolated to your tenant.
- 03
Tenant isolation is enforced at the data layer
Isolation lives in the database itself (not just the application), so a missed filter fails closed and returns nothing rather than leaking.
Built for the regulations your team faces.
In AI-assisted hiring the employer is the regulated party. These regimes turn on auditability and candidate notice: NYC Local Law 144 requires an annual independent bias audit and advance candidate notice, and the EU AI Act treats hiring as high-risk under Annex III. CertAIn supports your review with the artifacts that work needs, shipping in the product today — a demographic-free bias-audit export your auditor can run an impact-ratio analysis against, written per-decision reasoning, an append-only activity log, and a tenant-editable candidate notice you deliver in your own flow.
We supply the audit inputs and the candidate-notice tooling. Attestations, conformity assessments, and final audits stay with your auditor.
How we handle your data.
- Encrypted in transit and at rest.
Integration credentials carry an extra layer of application-level encryption with key rotation.
- Encrypted file storage, isolated per customer.
Resumes and photos live on encrypted persistent disk, partitioned per tenant, validated on upload.
- A human always decides.
No AI output changes a candidate’s state on its own. Acting on a recommendation is a deliberate, logged human choice.
- US-region today.
EU-region infrastructure ships with the first enterprise agreement that requires it.
The depth your reviewer needs.
Incident response.
Confirmed security incidents are disclosed to affected tenants without undue delay, followed by a written post-mortem with corrective actions. Security contact: security@certainhr.ai. A member of the team responds directly.