Security & data
You are about to put your entire business into a piece of software. These are the answers to the questions you should be asking — including the ones we would rather you did not.
StaffingCRM is delivered as your own instance on infrastructure you choose. Most agencies run it in an Indian region, which keeps candidate data inside the country and makes the DPDP question a short one. There is no shared multi-tenant database holding your candidates next to a competitor's.
Every request is HTTPS. Passwords are hashed with Argon2id — not encrypted, hashed, so nobody including us can read one back. Third-party keys you paste into Settings are encrypted in the database with a key held outside it.
A short-lived signed cookie carries who you are; a long refresh token in the database keeps you signed in and is single-use. Removing a teammate ends their session immediately rather than whenever their cookie happens to expire.
Roles decide who works the desk, who sees rates and margins, and who changes the workspace. A recruiter can be held to their own client accounts — and that rule is applied in the queries themselves, so it holds on the reports and the CSV export too, not only on the buttons.
Every stage move, email, decision, export and settings change is written to an append-only activity log with who did it and when. It is on screen in Settings, filterable, and it is the same log the product itself reads — not a separate feed that can quietly stop.
An Aadhaar or PAN number typed into the document vault is reduced to its last four characters on the way in. The full number is never written to the database, so it is not in a backup either.
The whole product is one application and one MySQL database. A nightly dump plus your provider's volume snapshots is a complete backup, restorable without us. We will help you set it up; we do not hold the only copy.
No analytics scripts, no session recording, no third-party tag on any signed-in page. The app talks to your database, your mail server, and whichever integrations you switch on yourself.
A page that only lists strengths is a page nobody believes.
AI features are optional and run on your own API key. Your candidates and clients are never used to train anything, by us or by the model provider under their commercial terms.
There is no shared talent pool, no cross-agency matching, and no arrangement where your candidates become someone else's search results. Your instance is yours.
Every module exports to CSV from inside the product, and invoices export in the format Tally and Zoho Books read. If you leave, you leave with everything, without asking us for it.
StaffingCRM does not currently hold ISO 27001 or SOC 2. Those audit an organisation, not a codebase, and we would rather say so than imply a certificate we do not have. What is above is what the software does, and every item is something you can verify on your own instance. If your procurement process needs a questionnaire filled in, send it — we answer them honestly, including where the answer is no.