Trust is the product.
Every AI decision in RecruitHorizon writes a receipt — what it saw, what it decided, which policy it followed. Every receipt is sealed into a tamper-evident, hash-chained ledger your auditors can verify. This page shows the machinery.
every claim on this page is verifiable in the product
sha-256 · hash-chained · append-only. Every event carries the hash of the one before it.
Follow one decision through the machine
Most hiring AI asks you to trust a black box. Ours is built the other way: the moment the AI acts, the evidence starts writing itself.
model: claude-haiku · 1.2s
The AI screens a candidate and makes a recommendation. Nothing about this moment is allowed to stay in the model's head.
The same moment, written down: score, rationale, model, confidence — and the policy thresholds in force. Receipts have no update path.
Each ledger event carries the hash of the one before it. Alter any record — even one byte — and verification reports the exact break.
Numbers from the schema, not the pitch deck
Every ledger event is sealed with SHA-256 and chained to the event before it.
Row-Level Security on every database table, beneath the per-company scoping every query already carries.
Every AI evaluation writes a receipt — score, rationale, model, and the policy in force. No update path.
The extended retention class defaults to seven years, and legal holds suspend deletion entirely.
Boring infrastructure. Deliberately.
No homegrown security experiments. Proven providers, layered barriers, and a literal implementation note on every claim so your technical reviewers can check our work.
Encryption in transit and at rest
Every connection runs over TLS. At rest, the database is encrypted by our managed Postgres provider — we don't roll our own crypto.
https everywhere · encrypted at rest (Supabase-managed)
Two-barrier tenant isolation
Every query is scoped to your company at the application layer, and Row-Level Security is enabled on every table beneath it. A bug would have to defeat both.
where: { companyId } · ENABLE ROW LEVEL SECURITY
Server-side authentication
Sessions are issued and validated by Supabase Auth, checked server-side in middleware on every request. Nothing trusts the client.
supabase.auth.getUser() · validated in middleware
Payments never touch us
Billing runs entirely through Stripe, PCI-DSS Level 1 certified. Card numbers never reach our servers or our database.
stripe checkout · zero card data stored
Email, authenticated and logged
Outbound mail is sent through SendGrid with DKIM and SPF, and every send is logged with recipient, subject, and delivery status.
EmailLog · DKIM · SPF · delivery status recorded
Managed, patched infrastructure
Hosting on Render with automated OS and runtime patching; Postgres on Supabase with automatic backups. Boring choices, on purpose.
render · supabase postgres · auto-patched
The law now asks for records
AI-hiring regulation is converging on one demand: show what the system did, and keep the evidence. RecruitHorizon is built to produce audit-ready records — not to make your legal determinations for you.
HB 3773
Amends the Illinois Human Rights Act, effective January 1, 2026: employers must notify candidates when AI is used in employment decisions, and are accountable for discriminatory use.
What you'll have: Decision receipts show what the AI did, when, and which policy it followed.
FEHA automated-decision rules
California's civil-rights regulations treat automated-decision system data as employment records — with a four-year retention requirement.
What you'll have: Configurable retention classes and checksum-verified exports keep those records producible.
Local Law 144
Requires independent bias audits and candidate notice for automated employment decision tools used on NYC candidates.
What you'll have: Decision-level records give your auditors real data to work from, not vendor assurances.
RecruitHorizon provides records and tooling; compliance obligations remain with the employer — consult counsel.
How we calculate time-saved claims
Trust extends to our own marketing. Every time-saved figure on this site derives from one published set of per-action constants:
Conservative per-action estimates of manual effort replaced. Actual savings vary by workflow complexity and team size. See the full methodology.
What security reviewers ask us
Read the receipts before you buy the software.
Start a trial, screen a candidate, and open the ledger — the audit trail runs from your first click. Or book a demo and we'll walk your security team through the machinery.

