Back to Trust Center

Vendor Risk Management & Sub-processors

Last Updated: January 9, 2026

Overview

CandidateSeekers utilizes a carefully selected group of third-party service providers to offer our platform. We perform due diligence on all vendors to ensure they meet our security and compliance standards (SOC 2, ISO 27001, GDPR).

Infrastructure & Hosting

  • Vercel

    Cloud hosting, Edge Functions, and Content Delivery Network (CDN).

    SOC 2 Type II
  • Supabase

    Core database (PostgreSQL), Authentication, and Real-time subscriptions (HIPAA-aligned infrastructure where applicable).

    SOC 2 Type IIHIPAA Aligned

Payment Processing

  • Stripe

    Payment processing, subscription management, and PCI compliance handling.

    PCI-DSS Level 1SOC 2 Type II

Communication

  • MailerLite / Resend

    Transactional emails (password resets, notifications) and marketing campaigns.

    GDPR Compliant
  • Google Workspace

    Internal email, document storage, and OAuth authentication provider.

    ISO 27001

Vendor Selection Policy

Before onboarding any new sub-processor, CandidateSeekers evaluates their:

  • Security certifications (SOC 2, ISO 27001).
  • Privacy compliance (GDPR, CCPA).
  • Business continuity and disaster recovery plans.

Vendor security posture is reviewed annually or upon material changes.