HiddenList
  • Features
  • Pricing
  • FAQ
Try for Free

HiddenList Trust Center

HiddenList is an AI-powered talent search and outreach platform used by recruiting teams at companies from fast-growing startups to global groups. Security and privacy are built into how we operate — and independently checked.

trust@hiddenlist.ai  ·  Last updated September 21, 2026

Used by teams at

Sea GroupSea Group
ByteDanceByteDance
foodpandafoodpanda
GrasshopperGrasshopper
Black Sesame TechnologiesBlack Sesame Tech
TabSquareTabSquare
Flo EnergyFlo Energy
StaffAnyStaffAny
ElitezElitez

Certifications & independent assessments

Passed · Sept 2026

ADA CASA Assurance Level 1

Google's App Defense Alliance assessment for apps with restricted Gmail access. Assessed by TAC Security. 48/48 controls passed, zero findings. Renewed annually.

0 High · 0 Medium

Authenticated security scan

Our own authenticated dynamic scan of app.hiddenlist.ai, Burp Suite Professional, September 2026. No high- or medium-severity issues. Not a third-party penetration test.

Aligned

GDPR & PDPA

We handle personal data in line with the EU GDPR and Singapore's PDPA and honour deletion/access requests. Not independently certified.

In progress

ISO/IEC 27001

Certification of our information security management system is under way with an engaged auditor. Certificate published here once issued.

Verified · Sept 2026

Google OAuth verification

Google's own review of our restricted Gmail scopes, approved. The CASA assessment above was the security component of this review.

Controls

Live in production today, verified as part of the CASA assessment.

Infrastructure & data location

  • App, database and search index hosted in Singapore
  • Files in Cloudflare R2, private buckets, generated keys only
  • Secrets encrypted at rest, injected at runtime, never in source code
  • Debug mode and directory listing disabled in production

Data protection

  • TLS 1.2+ enforced everywhere, with HSTS
  • Mailbox tokens encrypted at rest (AES-256-GCM)
  • Passwords hashed with bcrypt, never stored in plain text
  • Credentials and payment details never logged
  • Card payments handled by Stripe — full numbers never touch us

Access control

  • Every record scoped to your company — enforced server-side, tested
  • Role-based permissions enforced on every request
  • Admin console requires Google sign-in with two-step verification
  • Staff access to customer data only when you ask for support

Authentication & sessions

  • Secure, HttpOnly, SameSite session cookies
  • Password change or logout invalidates other sessions
  • One-time codes and magic links: single-use, expire in 30 minutes
  • Sign-in and OTP endpoints rate-limited against brute force

Application security

  • Protected against SQL/OS/template injection, XSS, CSRF, SSRF, open redirects
  • File uploads validated by size, type and actual content
  • Dependencies audited against known vulnerabilities

Connected Gmail & Outlook accounts

  • We only read replies to messages sent through HiddenList — never the rest of your inbox
  • Only messages you write or schedule are sent
  • Disconnect any time: Gmail access is revoked at Google immediately; the Outlook token is deleted immediately and access lapses (Microsoft has no per-token revoke)
  • Exact permissions requested, per provider: see IT administrators below

AI & your data

  • AI understands search, evaluates candidate fit, detects candidate replies
  • Your data is never used to train our AI providers' models
  • HiddenList assists sourcing; it does not make hiring decisions

Privacy & deletion

  • We never sell your data or share it beyond the sub-processors below
  • Disconnecting a mailbox deletes its token immediately
  • Full deletion on request to trust@hiddenlist.ai
  • Details: Privacy Policy · Terms of Service

Sub-processors

Service providers that may process customer data on our behalf.

Fly.ioApplication hosting & database · Singapore
ElasticSearch index · Singapore
CloudflareFile storage (R2) · Global
GoogleSign-in, Gmail sending & replies · Global
MicrosoftSign-in, Outlook sending & replies · Global
UnipileLinkedIn & WhatsApp messaging · EU
OpenAISearch & candidate-fit AI, no training · US
StripePayments & subscriptions · Global

Documents

ADA CASA AL1 assessment report (TAC Security, Sept 2026)Request access
Security scan summary (Sept 2026)Request access
Security questionnaire (CAIQ / custom)Request
Privacy PolicyOpen
Terms of ServiceOpen

For IT administrators: approving HiddenList for your mailboxes

If your organisation restricts third-party apps, a recruiter connecting Gmail or Outlook will see "access blocked" or "needs admin approval". An administrator approves HiddenList once, using the app IDs below.

Google OAuth client ID: 401664883751-5ttg5nm8sfge0movc72t5g7re84el37n.apps.googleusercontent.com
Microsoft application (client) ID: 8ce37af3-f9d8-4816-a669-c0b212a7d690

Google Workspace (super admin)

  1. Admin console → Security → Access and data control → API controls.
  2. Under Configured apps, click Configure new app.
  3. Search the Google client ID above and select the app (listed as HiddenList).
  4. Choose the org units/groups, Continue.
  5. Set access to Trusted, Continue, Finish.

Requests: sign-in identity (openid, email, profile), gmail.send, gmail.readonly.

Microsoft 365 (Entra admin)

  1. One click: open this admin-consent link, review, click Accept.
  2. Or: Entra admin center → Enterprise apps → search HiddenList/TalentGPT → Security → Permissions → Grant admin consent.
  3. Tenants using consent requests: approve under Enterprise apps → Admin consent requests.

Requests: Mail.ReadWrite (send & read replies in the connected mailbox), User.Read, offline_access.

Questions from your IT or security team: trust@hiddenlist.ai.

Frequently asked questions

Where is my data hosted?

Singapore: application, database and search index. Files in Cloudflare R2.

Do you use my data to train AI models?

No. Your data is never used to train our models or our providers' models.

Can HiddenList read my whole inbox?

No. Only replies to messages sent through HiddenList. Revoke access any time from Settings.

Is HiddenList SOC 2 or ISO 27001 certified?

ISO/IEC 27001 is in progress with an engaged auditor. Today our controls are independently verified through Google's ADA CASA AL1 assessment (48/48 controls, September 2026) and our own authenticated security scan.

Our company blocks third-party apps. How do we approve HiddenList?

An administrator approves it once — see IT administrators below. About two minutes.

How do I delete my data?

Disconnect a mailbox in Settings, delete a project, or email trust@hiddenlist.ai for full account deletion.

Who can see my data inside HiddenList?

Your team, and — only when you ask for help — authorised staff. Every company's records are isolated from every other's.

Report a security concern

Found a vulnerability, or need a security review for procurement? Email trust@hiddenlist.ai. We acknowledge reports within two business days and never take legal action against good-faith security research.