HiddenList Trust Center
HiddenList is an AI-powered talent search and outreach platform used by recruiting teams at companies from fast-growing startups to global groups. Security and privacy are built into how we operate — and independently checked.
trust@hiddenlist.ai · Last updated September 21, 2026
Used by teams at
Sea Group
ByteDance
foodpanda
Grasshopper
Black Sesame Tech
TabSquare
Flo Energy
StaffAny
Elitez
Certifications & independent assessments
ADA CASA Assurance Level 1
Google's App Defense Alliance assessment for apps with restricted Gmail access. Assessed by TAC Security. 48/48 controls passed, zero findings. Renewed annually.
Authenticated security scan
Our own authenticated dynamic scan of app.hiddenlist.ai, Burp Suite Professional, September 2026. No high- or medium-severity issues. Not a third-party penetration test.
GDPR & PDPA
We handle personal data in line with the EU GDPR and Singapore's PDPA and honour deletion/access requests. Not independently certified.
ISO/IEC 27001
Certification of our information security management system is under way with an engaged auditor. Certificate published here once issued.
Google OAuth verification
Google's own review of our restricted Gmail scopes, approved. The CASA assessment above was the security component of this review.
Controls
Live in production today, verified as part of the CASA assessment.
Infrastructure & data location
- App, database and search index hosted in Singapore
- Files in Cloudflare R2, private buckets, generated keys only
- Secrets encrypted at rest, injected at runtime, never in source code
- Debug mode and directory listing disabled in production
Data protection
- TLS 1.2+ enforced everywhere, with HSTS
- Mailbox tokens encrypted at rest (AES-256-GCM)
- Passwords hashed with bcrypt, never stored in plain text
- Credentials and payment details never logged
- Card payments handled by Stripe — full numbers never touch us
Access control
- Every record scoped to your company — enforced server-side, tested
- Role-based permissions enforced on every request
- Admin console requires Google sign-in with two-step verification
- Staff access to customer data only when you ask for support
Authentication & sessions
- Secure, HttpOnly, SameSite session cookies
- Password change or logout invalidates other sessions
- One-time codes and magic links: single-use, expire in 30 minutes
- Sign-in and OTP endpoints rate-limited against brute force
Application security
- Protected against SQL/OS/template injection, XSS, CSRF, SSRF, open redirects
- File uploads validated by size, type and actual content
- Dependencies audited against known vulnerabilities
Connected Gmail & Outlook accounts
- We only read replies to messages sent through HiddenList — never the rest of your inbox
- Only messages you write or schedule are sent
- Disconnect any time: Gmail access is revoked at Google immediately; the Outlook token is deleted immediately and access lapses (Microsoft has no per-token revoke)
- Exact permissions requested, per provider: see IT administrators below
AI & your data
- AI understands search, evaluates candidate fit, detects candidate replies
- Your data is never used to train our AI providers' models
- HiddenList assists sourcing; it does not make hiring decisions
Sub-processors
Service providers that may process customer data on our behalf.

Fly.ioApplication hosting & database · Singapore

ElasticSearch index · Singapore

CloudflareFile storage (R2) · Global

GoogleSign-in, Gmail sending & replies · Global

MicrosoftSign-in, Outlook sending & replies · Global

UnipileLinkedIn & WhatsApp messaging · EU

OpenAISearch & candidate-fit AI, no training · US

StripePayments & subscriptions · Global
Documents
ADA CASA AL1 assessment report (TAC Security, Sept 2026)Request access
Security questionnaire (CAIQ / custom)Request
For IT administrators: approving HiddenList for your mailboxes
If your organisation restricts third-party apps, a recruiter connecting Gmail or Outlook will see "access blocked" or "needs admin approval". An administrator approves HiddenList once, using the app IDs below.
Google OAuth client ID: 401664883751-5ttg5nm8sfge0movc72t5g7re84el37n.apps.googleusercontent.com
Microsoft application (client) ID: 8ce37af3-f9d8-4816-a669-c0b212a7d690
Google Workspace (super admin)
- Admin console → Security → Access and data control → API controls.
- Under Configured apps, click Configure new app.
- Search the Google client ID above and select the app (listed as HiddenList).
- Choose the org units/groups, Continue.
- Set access to Trusted, Continue, Finish.
Requests: sign-in identity (openid, email, profile), gmail.send, gmail.readonly.
Microsoft 365 (Entra admin)
- One click: open this admin-consent link, review, click Accept.
- Or: Entra admin center → Enterprise apps → search HiddenList/TalentGPT → Security → Permissions → Grant admin consent.
- Tenants using consent requests: approve under Enterprise apps → Admin consent requests.
Requests: Mail.ReadWrite (send & read replies in the connected mailbox), User.Read, offline_access.
Questions from your IT or security team: trust@hiddenlist.ai.
Frequently asked questions
Where is my data hosted?
Singapore: application, database and search index. Files in Cloudflare R2.
Do you use my data to train AI models?
No. Your data is never used to train our models or our providers' models.
Can HiddenList read my whole inbox?
No. Only replies to messages sent through HiddenList. Revoke access any time from Settings.
Is HiddenList SOC 2 or ISO 27001 certified?
ISO/IEC 27001 is in progress with an engaged auditor. Today our controls are independently verified through Google's ADA CASA AL1 assessment (48/48 controls, September 2026) and our own authenticated security scan.
Our company blocks third-party apps. How do we approve HiddenList?
An administrator approves it once — see IT administrators below. About two minutes.
How do I delete my data?
Disconnect a mailbox in Settings, delete a project, or email trust@hiddenlist.ai for full account deletion.
Who can see my data inside HiddenList?
Your team, and — only when you ask for help — authorised staff. Every company's records are isolated from every other's.
Report a security concern
Found a vulnerability, or need a security review for procurement? Email trust@hiddenlist.ai. We acknowledge reports within two business days and never take legal action against good-faith security research.