Security & trust

Built to be audited.

Hiring runs on sensitive data and consequential decisions. Twynit's answer isn't a policy page — it's architecture: isolation enforced in code, an immutable ledger under every action, and a named human responsible for every decision. This page states what is true today, plainly.

01

How the AI is kept accountable

The most important thing about hiring AI is that a human stays responsible for every decision. In Twynit, that isn't a policy — it's how the product is built.

The Twin proposes; a named human approves

No consequential action happens without a person approving it, or without an autonomy grant that person made and can revoke. Scoring, ranking, and filtering are deterministic math and rules — the reasoning parts of the product, not the deciding part.

Explainable by architecture

Every recommendation unfolds into the exact evidence behind it, mapped to the job-related criteria the recruiter wrote. There is no naked score anywhere in the product, and the scoring dimensions are never demographic proxies.

Honest about uncertainty

When the evidence can't establish something, the Twin says so and turns it into an interview question. The Memory page shows the Twin's own prediction accuracy over time, including where it's weak.

Bias-guarded inputs and outputs

Discriminatory queries are detected and blocked, and generated language is held to job-related criteria only — never age, gender, or culture-fit proxies. Evaluations attribute to skills, experience, and screening answers.

02

Auditability

An immutable, append-only ledger

Every action — by a human or the Twin — is recorded with actor, timestamp, action, evidence state, and undo status. Entries are never edited or deleted; an undo marks its entry reversed. The ledger is searchable and exportable from Settings → Audit.

72-hour undo on consequential actions

Actions are reversible for 72 hours from their receipt. Undoing an automated action also revokes that automation until it's re-granted — trust that's spent must be re-earned.

Answers in under a minute

An admin can reconstruct the full basis for any decision — who made it, when, and on what evidence — and export it, typically in well under a minute.

03

Data protection

Tenant isolation, enforced in code

Every workspace's data is isolated at the query layer. Isolation is enforced on every read by a global tenant guard, not left to convention — unscoped queries fail safe rather than leak.

Encryption in transit and at rest

All traffic is encrypted with TLS; stored data and file attachments are encrypted at rest. Integration credentials are stored encrypted.

Role-based access control

Access follows defined roles — Admin, Recruiter, Hiring Manager, Guest. Guests and interviewers see only what a specific request or search requires; sensitive context like compensation is restricted.

Retention, deletion, and export

Retention policies run on your schedule. Candidate-data deletion requests are handled from Settings → Data, and full workspace export — people, searches, decisions, and the audit ledger — is self-serve.

04

Enterprise readiness

SSO and SCIM

Single sign-on and SCIM provisioning are available for enterprise workspaces, so access follows your identity provider and deprovisioning is automatic.

Write-back you can trust

Every write to an external system (ATS, HRIS, calendar) names its destination in a receipt and is undoable. Write-back failures surface as warnings with retry — never silently.

Agency data walls

For agencies, knowledge is client-scoped by design: one client's outcome learnings never inform another client's scorecards. The wall is structural, not a permission setting.

Availability and reliability

Health and readiness are continuously monitored across the database, queues, and AI dependencies. The AI layer runs behind circuit breakers and key rotation so a provider hiccup degrades gracefully rather than failing hard.

Have a security review to run?

We'll walk your team through the architecture and answer the hard questions directly.