Product · Security & Compliance

Built like your reputation depends on it

Because in this business, it does.

14 days · Full access · No credit card

Roles and permissions settings in Smoothire: per-role permission matrix, organisation-wide two-factor authentication, append-only audit log and one-click workspace export.
2FA enforced org-wide

How does Smoothire handle security and compliance?

Smoothire ships with role-based access control, two-factor authentication, an append-only audit log, soft-delete on everything, one-click workspace export, and a configurable compliance rules engine — from the first day, on every plan.

Access, exactly as granular as you need

Admin, Manager, and Recruiter roles with editable permissions — plus custom roles when your structure doesn’t fit the mold. Permission changes are themselves audit-logged.

Roles and permissions settings in Smoothire: per-role permission matrix, organisation-wide two-factor authentication, append-only audit log and one-click workspace export.
[SHOT: append-only audit log]

A history nobody can quietly edit

Every meaningful action lands in an append-only activity log. Corrections happen by adding a reversal with a reason — never by erasing. Your audit trail is an asset, not a liability.

Compliance as configuration, not custom code

Rules like "no CV without education can be published" or "this client requires candidate consent" are settings you switch on — globally, per client, or per role. Consent is captured with the candidate’s own email as evidence.

[SHOT: compliance rules engine]
[SHOT: one-click workspace export]

Your data is yours. Provably.

Soft-delete everywhere (nothing is ever silently destroyed), encrypted in transit and at rest, and a one-click export of your entire workspace — the feature vendors hate and honest ones ship. Our privacy posture covers GDPR, India’s DPDP Act, and CCPA.

Common questions

Is Smoothire SOC 2 certified?

Certification is on our roadmap; our practices are built for it. Ask us for the current security overview.

Where is data hosted?

Ask us for the current hosting and data-residency overview — we’ll share it plainly.

Can I enforce 2FA for my whole team?

Yes — organisation-wide 2FA enforcement is a setting.

See your agency run on Smoothire.

Bring your openings, your candidates, your clients — we’ll migrate them free.

14-day full trial · No credit card · Free assisted migration during our launch period