Trust Center · Security
Security at KitaHQ
KitaHQ supports customer security review through documented technical and organizational measures designed for the risks of the service. This page explains those controls, KitaHQ’s evidence process and the responsibilities shared with employers and users.

Hiring context
CVs · interview responses · transcripts · recordings · reports
Core Security Controls
These controls support transparency, consistent criteria and human accountability. Their effectiveness also depends on employer configuration, criteria, safeguards and human use.

Encryption
KitaHQ uses encryption for data in transit and at rest.

Access Controls
KitaHQ uses role-based access controls and multi-factor authentication to limit access according to assigned responsibilities.
Employers control which authorized users can access their KitaHQ workspace and should remove access when a person no longer requires it.
Employers control which authorized users can access their KitaHQ workspace and should remove access when a person no longer requires it.

Monitoring and Vulnerability Scanning
KitaHQ uses monitoring and vulnerability scanning to identify security issues and support investigation and remediation.

Incident Response
KitaHQ maintains documented incident-response procedures for identifying, containing, investigating and responding to security incidents.
Where a personal-data breach triggers a legal or contractual notification obligation, KitaHQ follows the applicable process and coordinates with affected customers as required.
Where a personal-data breach triggers a legal or contractual notification obligation, KitaHQ follows the applicable process and coordinates with affected customers as required.

CONTROL REFERENCE
EVIDENCE
Security Assurance
KitaHQ internally maps its security procedures to selected security-related criteria within the AICPA Trust Services Criteria used in SOC 2 examinations.
KitaHQ maintains this mapping as an internal control reference and supports customer security review by providing available evidence for documented controls through the appropriate review process.
KitaHQ maintains this mapping as an internal control reference and supports customer security review by providing available evidence for documented controls through the appropriate review process.
CONTROL
EVIDENCE
REVIEW
Data Lifecycle
Data Handling and Service Providers
KitaHQ uses cloud and AI-processing service providers to operate the service. Personal data may be processed outside the country where it was collected, subject to the transfer basis and safeguards described in the Privacy Notice.
KitaHQ does not use candidate data, including interview content, to train KitaHQ or third-party AI models. More information about data categories, recipients, international processing and retention is available in the Privacy Notice.
KitaHQ does not use candidate data, including interview content, to train KitaHQ or third-party AI models. More information about data categories, recipients, international processing and retention is available in the Privacy Notice.
Data Retention and Deletion
Retention periods vary by data type and system. KitaHQ retains recruitment data according to documented employer instructions, applicable customer agreements, legal and security needs, and the Privacy Notice. A specific period applies only where it covers a defined data category and has been verified across the relevant systems and providers.
Employers should configure their recruitment processes and internal retention practices according to their legal and business requirements.
Employers should configure their recruitment processes and internal retention practices according to their legal and business requirements.
Shared Responsibility
Security depends on both KitaHQ and the employer using the service.
KitaHQ & Employers
KitaHQ is responsible for controls within the service and its operating environment. Employers are responsible for account administration, appropriate user access, secure devices, strong authentication practices, lawful data collection and prompt notification of suspected misuse.
Candidates & Users
Candidates and users should protect invitation links and account credentials and should not share them with unauthorized people.
Reporting a Security or Technical Concern
For a technical problem, contact support@kitahq.com. Include enough information for KitaHQ to investigate, but do not send passwords or unnecessary sensitive candidate information by email.
Privacy questions and rights requests concerning KitaHQ’s own processing may be sent to privacy@kitahq.com.
Privacy questions and rights requests concerning KitaHQ’s own processing may be sent to privacy@kitahq.com.
Documented Security Assurance
KitaHQ’s public security assurance is supported by the following documented controls:
01
Encryption in transit and at rest.
02
Role-based access controls with multi-factor authentication.
03
Monitoring and vulnerability scanning.
04
Documented incident-response procedures.
05
Security procedures internally mapped to selected security-related criteria within the AICPA Trust Services Criteria used in SOC 2 examinations.
This page covers documented controls and available evidence. Contractual service levels, independent reports and deployment-specific legal assessments are addressed through the appropriate customer review and agreement.
Country-Specific Security Information
KitaHQ’s public security statements are based on documented controls: encryption in transit and at rest, role-based access controls, multi-factor authentication, monitoring, vulnerability scanning and documented incident-response procedures.
Those procedures are mapped internally to selected security-related criteria within the AICPA Trust Services Criteria used in SOC 2 examinations, and available control evidence can be provided through the appropriate customer security-review process. Infrastructure-provider details can be shared where relevant to that review.

United States
United States security and breach duties vary by state, sector and the type of personal information involved. KitaHQ applies the documented controls described above and assesses incidents for contractual and legally required notices. Where a state privacy law applies, reasonable security and any required consumer or regulator notification remain tied to that law and the relevant roles.

United Kingdom
Where the UK GDPR applies, controllers and processors must use security appropriate to the risk and follow applicable personal-data-breach assessment and notification duties. KitaHQ’s documented controls support those obligations, while the hiring employer remains responsible for its own access, configuration, users and incident decisions.

Canada
Canadian private-sector privacy law requires safeguards appropriate to the sensitivity of personal information and may require breach records and notification where the statutory threshold is met.
KitaHQ’s documented technical and organizational controls support that approach. Customers remain responsible for their account permissions, exports, devices and any employer-controlled response.
KitaHQ’s documented technical and organizational controls support that approach. Customers remain responsible for their account permissions, exports, devices and any employer-controlled response.

Australia
Australian Privacy Principle 11 requires covered entities to take reasonable steps to protect personal information, and the Notifiable Data Breaches scheme may require notification of eligible breaches.
KitaHQ’s documented access, encryption, monitoring, scanning and response controls support risk-based protection; customers remain responsible for their own user access and exported data.
KitaHQ’s documented access, encryption, monitoring, scanning and response controls support risk-based protection; customers remain responsible for their own user access and exported data.

New Zealand
Information Privacy Principle 5 requires reasonable security safeguards, including when information is provided to a service provider, and the Privacy Act 2020 requires notification of notifiable privacy breaches.
KitaHQ’s security and incident-response controls support these requirements, while employers remain responsible for their own users, permissions and exports.
KitaHQ’s security and incident-response controls support these requirements, while employers remain responsible for their own users, permissions and exports.

Singapore
Singapore’s PDPA requires reasonable security arrangements, retention limitation, appropriate overseas-transfer safeguards and notification of notifiable data breaches.
Momentum Spark Pte. Ltd. maintains the documented KitaHQ controls described on this page and works with customers according to the relevant role and contract. These controls support the applicable security and incident-management responsibilities.
Momentum Spark Pte. Ltd. maintains the documented KitaHQ controls described on this page and works with customers according to the relevant role and contract. These controls support the applicable security and incident-management responsibilities.

Malaysia
Malaysia’s PDPA and its 2024 amendments strengthen obligations relevant to security, data-protection responsibility and breach notification. KitaHQ publishes controls supported by current protocols and retains internal evidence for those statements. Employers remain responsible for their users, permissions, exports and recruitment handling.

Indonesia
Indonesia’s PDP Law requires controllers and processors to protect Personal Data and contains incident-notification duties. KitaHQ’s documented security and response controls support risk-based protection of candidate and recruiter data. Employers remain responsible for the security of their own accounts, access assignments, downloaded files and subsequent use.

Germany and the European Union
GDPR Articles 32-34 require risk-appropriate security and personal-data-breach assessment and notification. Germany may add competent-authority and employment-context requirements.
KitaHQ supports these obligations through the verified control list and its internal mapping to selected security-related criteria within the AICPA Trust Services Criteria used in SOC 2 examinations. Employers remain responsible for deployment-specific controller or deployer duties.
KitaHQ supports these obligations through the verified control list and its internal mapping to selected security-related criteria within the AICPA Trust Services Criteria used in SOC 2 examinations. Employers remain responsible for deployment-specific controller or deployer duties.
Explore KitaHQ Trust
Responsible AI
Learn what KitaHQ's AI processes, what outputs it creates, how those outputs should be interpreted, where automation may occur and how human responsibility is maintained.
Fair Hiring Practices
See how job-related criteria, structured interviews, recruiter reviews, accommodations and employer responsibilities fit together.
Candidate Guide
Understand how to prepare for a KitaHQ AI video interview, how AI is used, how to request help and where hiring decisions are made.
.png)
.avif)