Compliance
Compliance you can show your works council.
AI that evaluates job candidates is high-risk under the EU AI Act. We built Mirage around that fact: people make every hiring decision, every score points to the candidate's own words, and candidates know they are speaking with an AI before the interview starts.
- GDPR
- EU AI Act · Annex III
- People decide
- No emotion recognition
- Databases in Frankfurt
Where we stand
Our status, item by item.
- GDPRPrivacy by design: purpose limitation, consent before AI interviews, data subject rights.Built into the product
- EU AI Act safeguards (Annex III, high-risk)Human oversight, transparency to candidates and traceable scores are part of the product today.Live
- EU AI Act conformity assessmentThe formal steps for high-risk systems — risk management, technical documentation, fairness baseline — are being prepared.In preparation
- Data processing agreement (Art. 28 GDPR)Available for company customers.On request
- SOC 2Planned. We will publish the report once an audit has taken place.Planned
- ISO 27001Planned, after SOC 2.Planned
Status as of October 2026. When a status changes, this page changes with it.
GDPR
Personal data, handled as if it were yours.
Hiring data is some of the most sensitive data a company holds. Mirage processes it for one purpose: the hiring process the candidate chose to enter.
Purpose-bound
Interview answers feed the evaluation of that application and, after review, the candidate's own skill profile.
No training on your data
We do not use candidate or customer data to train AI models.
Consent before every AI interview
Candidates confirm a versioned consent notice before the interview can start: what is recorded, how AI is used, and that a person stays responsible.
Rights on request
Access, rectification, erasure, restriction and portability are handled through privacy@miragescouting.de, as set out in our privacy policy.
Transparent transfers
Some processors, such as AI model providers, operate outside the EEA. Those transfers rely on EU Standard Contractual Clauses.
Defined retention
Retention periods for accounts and interview data are set out in our privacy policy. Candidates can ask for earlier deletion.
EU AI Act
High-risk by law. Treated that way in the product.
AI that evaluates job candidates falls under Annex III of the EU AI Act. These safeguards are part of how Mirage works today, not a policy PDF.
People decide
Mirage recommends, your team decides. The software never rejects, advances or moves an application on its own.
Every score shows its evidence
Each skill score sits next to the candidate's own words from the interview, so reviewers check the reasoning instead of trusting a number.
Override built in
Hiring managers can overrule any AI assessment. The report is labelled as an AI-assisted assessment, not as a decision.
Candidates are informed
Before an AI interview, candidates learn that they are speaking with an AI, what is recorded and how the result is used.
Role criteria only
Scores are computed from the interview transcript against the skills defined for the role. Voice, accent, appearance and emotional state are not scoring inputs.
Decisions are recorded
Interview decisions are written to a decision journal, so an outcome can be traced and reviewed in an audit.
What Mirage does not do
- No emotion recognition from voice or face
- No biometric categorisation
- No automated rejection of applicants
- No analysis of facial expressions or appearance
Human oversight
How a hiring decision is made on Mirage.
Five steps. The AI contributes evidence in two of them. A person owns the decision.
- Step 1CandidateCandidate consentsA versioned consent screen comes before any AI interview.
- Step 2AIStructured interviewThe same rubric for every candidate in the role, in German or English.
- Step 3AIEvidence-backed assessmentA score per skill on a 0–10 scale, each with a quote from the interview.
- Step 4PeopleRecruiter reviewYour team reads the evidence, can overrule any score and adds its own judgement.
- Step 5PeopleA person decidesOnly a person moves the application forward. The decision is recorded.
AI contributes in steps 2 and 3. Steps 4 and 5 are always human.
Security & hosting
Where your data lives and who can see it.
Databases in Frankfurt
Our application databases run in the EU, in Frankfurt, Germany.
Encrypted in transit and at rest
Connections use TLS, and stored data is encrypted at rest.
Access per organisation
Your team sees your jobs and candidates. Other companies on Mirage do not.
Authenticated services
Internal services only accept calls that carry a valid service credential. Calls without one are refused.
For your DPO and works council
The documents procurement asks for.
Bring the questions to the first call. We send what your review needs.
We share documents after a short call, so you receive the version that fits your setup.
- Data processing agreement (Art. 28 GDPR)
- Technical and organisational measures (TOMs)
- List of sub-processors, including AI model providers
- Description of the AI system, its purpose and its human oversight
- Information for your works council (§ 87 BetrVG)
FAQ
Questions DPOs and works councils ask us.
Is Mirage compliant with the EU AI Act?
Recruiting AI is a high-risk use case under Annex III. The safeguards that category requires are live in the product: human decisions, transparency to candidates and traceable, evidence-backed scores. The formal conformity assessment is in preparation, and we disclose its status in every procurement review.
Does the AI reject candidates?
No. Mirage gives a recommendation with evidence. Only a person on your team can move, advance or reject an application.
Where is our data stored?
Our application databases run in Frankfurt (EU). Some processors, such as AI model providers, operate outside the EEA; those transfers use EU Standard Contractual Clauses. The sub-processor list is part of our compliance documents.
Do you train AI models on our candidates' data?
No. Candidate and customer data is not used to train AI models.
Which AI models does Mirage use?
Interviews and evaluations run on models from established providers, including Google (Gemini), Anthropic (Claude) and OpenAI, as listed in our privacy policy.
Can a candidate ask for a human review?
Yes. Only a person can make a decision in Mirage, and reviewers see the evidence behind every score. Candidates can also request a human review of their evaluation by writing to privacy@miragescouting.de.
Is Mirage SOC 2 or ISO 27001 certified?
Not yet. SOC 2 and ISO 27001 are planned. We would rather say that plainly than show a badge we do not hold.
Do we need our works council's agreement?
Often, yes. In Germany, systems that evaluate performance or behaviour usually fall under co-determination (§ 87 BetrVG). We provide a description of the system and its safeguards to support your works council's review.
Bring your DPO to the first call.
In 30 minutes we walk through data flows, human oversight and the documents your review needs.