What Greenhouse publishes about its security, privacy and use of your data, with a link to the page each fact came from. Checked October 10, 2026.
"Not found" means our reader didn't find it on the public pages it could read; the vendor may still publish it.
Statements differ between pages
Greenhouse's own words (greenhouse.com/ai-principles):
It meets regularly and has the authority to block features that don’t meet our standards. Customer data is never used for AI training Greenhouse does not use personal data from customers to train internal LLMs, proprietary models or third-party models.
Vendors often have different rules for consumer or free plans and for business or enterprise plans. Check the terms for the plan you would use.
Provide your information to employers seeking candidates with your skills and background, as referenced in the MyGreenhouse User Agreement. As part of this processing, we may use your Personal Information to improve, develop, and provide products and services, develop and tr…
greenhouse.com/privacy-policy
Different pages say different things. This is often a split between business plans and free or consumer plans. Read each quote for the plan you would use.
| Certification or report | Mentioned on |
|---|---|
| SOC 2 Type II | greenhouse.com/security |
| SOC 1 | greenhouse.com/security |
| ISO/IEC 27001 | greenhouse.com/security |
| ISO/IEC 27701 | greenhouse.com/security |
| ISO/IEC 42001 | greenhouse.com/security |
| PCI DSS | greenhouse.com/security |
Privacy laws and frameworks mentioned: GDPR, CCPA/CPRA, EU-U.S. Data Privacy Framework. These are laws the vendor says it follows, not certifications.
A certification on a website is a claim. For anything sensitive, ask Greenhouse for the SOC 2 report or ISO certificate.
Greenhouse publishes its subprocessor list at greenhouse.com/subprocessors-in-use, but it couldn't be read automatically. Open it directly.
| SSO / SAML | Mentioned |
| SCIM provisioning | Mentioned |
| Multi-factor authentication | Mentioned |
| Encryption at rest | Not found |
| Encryption in transit | Mentioned |
| Penetration testing | Mentioned |
| Bug bounty / disclosure program | Mentioned |
| Audit logs | Mentioned |
| Data residency | Not found |
| security.txt contact | security@greenhouse.io |
| Trust / security center | greenhouse.com/security |
| Privacy policy | greenhouse.com/privacy-policy |
| Subprocessor list | greenhouse.com/subprocessors-in-use |
| Data processing agreement (DPA) | greenhouse.com/data-processing-addendum |
| AI policy | greenhouse.com/ai-principles |
| Terms | Not found |
| Status page | status.greenhouse.io |
| Check | Points | Result |
|---|---|---|
| Security or trust page | 15 | Yes |
| Certifications listed | 20 | Yes |
| Privacy policy | 10 | Yes |
| Subprocessor list | 15 | Yes |
| DPA available | 10 | Yes |
| AI training policy stated | 15 | Yes |
| security.txt contact | 5 | Yes |
| Status page | 10 | Yes |
The score measures how much of a standard security review our reader could answer from Greenhouse's public pages. It is not a rating of how secure Greenhouse is, and a "No" can mean the document exists where our reader couldn't see it.
Get the same profile for any vendor in seconds, or let your AI agent do it with Stormap's free MCP server.
Adyen · Ashby · BILL · BambooHR · Brex · Carta · Chargebee · Culture Amp · Deel · Expensify · Justworks · Lattice
Source: Greenhouse's own public website (6 pages read on October 10, 2026). Stormap is not affiliated with Greenhouse. Facts are what the vendor publishes about itself; certifications are claims, not verified audit reports. Something wrong or out of date? Pages are re-checked every two weeks.