Skip to content
Security & Trust

Security and trust,
built into every layer.

Careers are personal data. We treat them that way — with databases in the EU, encryption in transit and at rest, and consent-first access controls.

Where we stand — claimed only when verified
GDPR
GDPR
Built in
EU D
EU databases
Frankfurt
ENCR
Encryption
Transit + rest
HUMA
Human oversight
Live
SOC
SOC 2
Planned
ISO
ISO 27001
Planned
How we protect your data

Layers, always on.

Encrypted in transit and at rest

Connections use TLS, and stored data is encrypted at rest.

Databases in the EU

Our application databases run in Frankfurt. Some processors, such as AI model providers, operate outside the EEA under EU Standard Contractual Clauses.

Consent-first access

Mentors and integrations only see the fields you choose to share.

Access per organisation

A company's team sees its own jobs and candidates, nobody else's. Internal services only accept calls with a valid service credential.

Report a security issue

Found a vulnerability? Write to privacy@miragescouting.de. We review every report.

Honest about status

We claim only what is verified. SOC 2 and ISO 27001 are planned — we will show evidence, not badges.

Your data, your control

You own it. Export or erase it.

We never sell your data and do not use it to train AI models. Mentors only see what you choose to share. Ask privacy@miragescouting.de for an export or deletion and we answer within the one month the GDPR allows.

  • ✓ Right to access, export and erasure
  • ✓ No data sold, no AI model training on your data
  • ✓ Granular sharing — you decide what mentors see
Your profile data
Encrypted at rest
TLS in transit ↓
EU database
Frankfurt, Germany
Shared only with consent ↓
Only what you share
Scoped per mentor / company
Security FAQ

The questions security teams ask.

Our application databases run in the EU, in Frankfurt. Some processors, such as AI model providers, operate outside the EEA; those transfers rely on EU Standard Contractual Clauses, as set out in our privacy policy.

Not yet. SOC 2 and ISO 27001 are planned. We would rather tell you honestly than claim a badge we do not hold.

Connections use TLS, and stored data is encrypted at rest.

No. We never sell customer data and do not use it to train AI models.

Access is scoped per organisation: a company's team sees its own jobs and candidates, nobody else's. Internal services refuse calls without a valid service credential.

Write to privacy@miragescouting.de with the details. We review every report and come back to you.

Need our security documentation?

Request our documentation — sub-processor list, data processing agreement and the current status of our audits.