Every third party below sits behind a configuration gate. With no credentials supplied, the platform runs on local, deterministic alternatives and no data leaves the deployment. A row applies to your workspace only if your provider has configured it. The two profile-sourcing providers carry a second, independent gate that must be set on top of the credential, so an API key alone cannot start them.
Anthropic — résumé parsing, applicant scoring, drafting, the recruiter assistant and employer-facing candidate summaries. Receives CV text, job descriptions and recruiter prompts. Engaged only when an API key is configured; otherwise scoring and drafting run locally and no candidate text is sent anywhere.
Microsoft Azure OpenAI and Voyage AI — text embeddings for semantic candidate-to-job matching. Receive candidate and job text through a projection that deliberately excludes name, employer and résumé summary. Only one is used, and only when configured; otherwise embeddings are computed locally.
The scoring model is name-blind. Voluntary self-identification data is never provided to it, and is structurally unreachable from the record the model reads.
Twilio SendGrid — transactional email and recruiter outreach. Receives recipient name, email address, message content and delivery events.
Twilio — WhatsApp and SMS candidate messaging. Receives phone number, message content and delivery status. Requires a paid entitlement, a pilot enrolment and an explicit per-channel switch by the workspace owner, in addition to the credential.
Google (Drive, Gmail, Calendar) and Microsoft (Graph) — CV import, inbound-email CV ingestion and interview calendar sync. Each is authorised by an individual recruiter through that provider's own sign-in; access tokens are stored encrypted and are never written to logs. Nothing is synced until a recruiter connects their own account.
Apify or Bright Data — job-board and professional-profile sourcing. An enrichment provider and a contact-reveal provider may also be configured to add structured profile details and verified contact information.
These process information about people who have not applied, so they carry the strictest gate on the platform: each requires both a credential and a separate confirmation that a data-processing agreement with that vendor is in place. With none configured, sourcing returns synthetic placeholder results and no real person's data is processed.
Sourced profiles that are never imported are automatically purged on a configurable schedule, and an erasure request reaches them independently of whether they were imported.
Microsoft Azure Blob Storage — storage for uploaded CVs, attachments and compliance documents, when object storage is configured. Files are encrypted by the platform before they are written. Otherwise files stay on the application host.
Stripe — subscription billing and hosted checkout. Receives billing contact and payment details. Stripe receives no candidate data.
A malware scanner inspects uploaded files. It is commonly deployed inside the customer's own boundary, in which case it is not a third party at all.
An operations directory receives a hired candidate's identity and role details — name, email, phone, location, role title and the names of verified documents — when one-click recruitment-to-operations conversion is switched on. It is usually a system the customer already controls, in which case it is a disclosure to the customer rather than to a third party; it is listed because the data leaves this platform either way.
Hosting provider and processing region depend on the deployment and are published by whoever operates it.