Security, Privacy and Responsible AI at TalliantSecurity, Privacy and Responsible AI at Talliant
1. Our approach
Talliant provides recruitment technology that can handle business and candidate information and can generate AI-assisted outputs. Security, privacy and responsible use therefore require documented ownership, risk assessment, technical safeguards, accurate notices, human accountability and evidence-based public statements.
This page describes Talliant’s current program direction. It is not a certification, audit opinion or guarantee that a particular legal framework applies to every customer or workflow.
2. Current assurance status
Talliant does not claim ISO 27001, ISO 9001, SOC 2 Type II, GDPR or DPDP certification/compliance through this page. A certification, audit report or legal-assurance statement may be communicated only when a current written record identifies the relevant Talliant entity, service scope, period, auditor or certification body, and applicable limitations.
Customers evaluating Talliant may request the current evidence available for appropriate review. Access may require confidentiality terms and will be limited to the relevant scope.
3. Security Program
Talliant’s security program is expected to address:
- security ownership and risk management;
- identity, authorization and tenant separation;
- secure development and change control;
- vulnerability management and security testing;
- logging, monitoring and incident handling;
- availability, backup and recovery planning;
- provider and subprocessor security review; and
- employee and support access.
Specific statements about infrastructure, regions, encryption, access reviews, test frequency, backup recovery or monitoring are shared only after the applicable configuration and operating evidence have been verified.
Security questions and good-faith vulnerability reports may be submitted to security@talliant.ai. Do not publicly disclose sensitive exploit details before Talliant has a reasonable opportunity to assess and address them.
4. Privacy program
Talliant’s privacy program is expected to maintain:
- a processing-purpose and data-flow inventory;
- clear customer/Talliant role allocation;
- timely website, business-user and candidate notices;
- specific choices where consent is appropriate and required;
- provider, location and international-transfer records;
- category-level retention and deletion processes;
- privacy-request and complaint handling; and
- testing and evidence for notice, consent, access and deletion behavior.
The Privacy Policy and Candidate Privacy Policy explain the relevant public information. A written policy is not treated as proof that a technical or operational control is working.
5. Responsible AI
- Depending on customer configuration, Talliant may support resume analysis, role-match indicators, scoring or ranking, calls, interviews, transcription, questions, summaries, insights and recommendations.
- Talliant does not describe these outputs as bias-free or as guaranteed predictions of job performance. AI outputs can be inaccurate, incomplete and sensitive to data, prompts, criteria and workflow configuration.
- The responsible-AI program is expected to address:
- documented intended purpose and prohibited uses;
- relevant data and question boundaries;
- evaluation of accuracy, reliability and potential unfair impact;
- model/provider/version and output lineage;
- appropriate customer and recruiter information;
- human accountability and escalation for material outcomes;
- monitoring, incident and change review; and
- provider restrictions on reuse or training where required.
- Hiring Organizations remain responsible for employment decisions and applicable employment and anti-discrimination obligations. Some workflow actions or communications may be automated when configured. Talliant does not claim that every action receives human review unless the specific workflow enforces and records it.
6. Providers and international processing
Talliant may use contracted providers for infrastructure, identity, AI, speech, audio/video, communications, scheduling, security, support or storage. Provider names, locations, retention and model-training positions are communicated only after technical and contractual verification.
Enterprise customers may request the current approved provider/subprocessor and transfer information through /contact.
8. Documentation requests
Organizations evaluating Talliant may use /contact to request current security, privacy, AI-governance, provider or contractual documentation. Talliant will identify the scope and status of material supplied and will not present a roadmap item as a completed control.
