HireRight, LLC

HireRight, LLC | Trust Center
Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.
Quick links
Quick links
Badges
Quick Summary
Documents & Knowledge Base FAQs
Announcements
Now Available - HireRight SOC 2 Type II 2026
Hello all,
Thank you for your patience as we waited for the public issuance of our SOC 2 Type II. It is now available for review in HireRight's Trust Portal at trust.hireright.com. We also have provided a separate status report document which contains management responses. These can be found in the "Audit Documentation (HireRight)" folder.
Thank you all for your cooperation and patience.
-HireRight Information Security
Cisco Catalyst SD-WAN - CVE 2026-20127 - N/A
HireRight is aware of Cisco Catalyst SD-WAN - CVE 2026-20127 and related vulnerabilities.
We are happy to share that our Network team confirmed we are not affected by these vulnerabilities: HireRight does not have SD-WAN controllers in our environment.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2026-20127
Stay safe out there!
React CVE - N/A
HireRight is aware of React Servers critical CVE-2025-55182. React servers are not used in the HireRight environment, so the CVE is not applicable for our services.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-55182
Stay safe out there!
Grafana CVE N/A
HireRight is aware of Grafana's critical CVE-2025-41115. Grafana is not used in the HireRight environment, so the CVE is N/A.
FMI: https://grafana.com/blog/2025/11/19/grafana-enterprise-security-update-critical-severity-security-fix-for-cve-2025-41115/
Stay safe out there.
Fortinet CVEs N/A
HireRight is aware of Fortinet's critica and high rated vulnerabilities: CVE-2025-58034 & CVE-2025-64446. Fortinet/ FortiOS is not used in the HireRight environment, so neither applies to our services.
FMI: https://www.cve.org/CVERecord?id=CVE-2025-58034 and https://www.cve.org/CVERecord?id=CVE-2025-64446
Stay safe out there.
F5 Vulnerability
We are aware of F5 vulnerability, as a precaution we have updated all F5 devices. There is no impact to client's data as a result of F5 vulnerabilities or the F5 updates. 24/7/365 monitoring by the SOC Team continues. Thank you and stay safe!
Cisco IOS/IOS XE CVE update
Re: Cisco IOS/IOS XE vulnerabilities. Our network engineering team has reviewed the advisories and confirmed again as of this morning that HireRight’s environment remains unimpacted; we have validated that appropriate safeguards are in place for mitigation and are applying vendor-recommended updates as part of our standard patch cycle. No customer data or systems have been affected as a result of Cisco vulnerabilities and we continue to monitor the situation closely and will take any additional actions recommended by Cisco or relevant security authorities.
Ref: https://nvd.nist.gov/vuln/detail/cve-2025-20333 & https://nvd.nist.gov/vuln/detail/CVE-2025-20352
Stay safe out there!
N/A GoAnywhere CVE-2025-10035
HireRight is aware of a critical security flaw (CVE-2025-10035, rated 10.0) related to a secure file transfer product called GoAnywhere which "allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection." HireRight is not using GoAnywhere and this CVE is not applicable.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-10035
Stay safe out there!
Cisco IOS/IOS-XE CVEs
We are aware of the CVE-2025-20333 & CVE-2025-20362 relating to Cisco IOS/IOS-XE. As per Cisco any type of workaround is temporary for this bug and to mitigate this bug we have to upgrade our all impacted network devices which is the plan and will require some time. We are currently performing tasks which are part of the temporary workaround to avoid the risk and after that we will plan for a permanent fix. Remember to check out https://trust.hireright.com for further updates on CVEs. Stay safe!
Salesloft Drift Inquiries
HireRight is aware of and has had a number of inquiries regarding Salesloft Drift (Ref: https://trust.salesloft.com/?uid=Drift%2FSalesforce+Security+Update).
HireRight has no current or recent direct relationship or integrations with Salesloft, and thus, is not impacted by this exfiltration event.
Thank you and stay safe out there.
N/A Adobe CVEs
HireRight is aware of Adobe EM Forms CVEs (CVE-2025-54253, CVE-2025-54254) and has confirmed that the impacted product is not used at HireRight, rendering the CVEs not applicable.
FMI: https://helpx.adobe.com/uk/security/products/aem-forms/apsb25-82.html
Stay safe out there.
N/A Netscaler CVEs
HireRight has received some inquiries about Citrix/ Netscaler CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424 (rated 9.2-8.7). HireRight is not using Citrix NetScaler in our environment, and all are not applicable as a result.
FMI: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938
Stay safe out there.
HireRight BCP-DR
UPDATE- now posted*
Hello All,
HireRight is aware that customers are requesting the BCP-DR Exercise report; it's currently with leadership for approval. It will be posted here as soon as we have it ready!
Stay safe out there, and thanks for your patience,
HireRight's InfoSec Team
SharePoint CVE-2025-53770 - No impact on HireRight
HireRight is aware of Critical (9.8) CVE-2025-53770, where Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. FMI: https://www.cve.org/CVERecord?id=CVE-2025-53770
No Impact: We have confirmed that the affected SharePoint Server versions are not present in our environment. All SharePoint services used for business are hosted in Microsoft 365, which is not affected.
Preventive Measures: As a precaution, we have implemented custom detection rules in our endpoint protection platform to identify and prevent exploitation patterns (e.g., ToolShell-related activity) in our environment.
Remediation Status: No remediation is required, as the vulnerable software is not present in our environment.
Stay safe!
SOC 2 Type II Released
Hello all,
Thank you for your patience as we waited for the delivery of our SOC 2 Type II. It is now available for review in HireRight's Trust Portal. Managerial responses are attached at the end of this document as opposed to being provided separately as was the case previously.
Stay safe out there (and happy reading)!
Microsoft CVE-2025-53770
HireRight is aware of Critical (9.8) CVE-2025-53770, where Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. This CVE does not apply to HireRight's environment; impacted versions of the software are not in use. FMI: https://www.cve.org/CVERecord?id=CVE-2025-53770
Stay safe out there.
SOC 2 Type II
UPDATE from JULY 16, 2025: THE AUDITOR SAYS SOC 2 TYPE II ETA ONE WEEK
Hello all,
HireRight is anticipating the final receipt of our 2024 SOC 2 Type II this month-- please keep an eye out for an announcement from us here, as we will upload it as soon as we possibly can! We know how many people are anticipating its release.
Thanks for your continued patience,
HireRight's InfoSec GRC Team
Updated Bridge Letter
HireRight's leadership team has released a new SOC 2 Type II Bridge Letter upon cusotmer request-- the new letter covers the time between the dated letter release and the delayed 2024 SOC 2 Type II release, which is now estimated to come in the first week of July, according to our auditor, BDO.
You can access this letter on our Trust Portal by navigating to https://trust.hireright.com/d/updated-6-2-25-bridge-letter-soc-report-delay/Ww1Rlq?lng=en
We continue to thank you for your patience, as we're very much ready to have that report too!
SOC 2 Type II Update
Hello All,
HireRight is waiting as eagerly as most of our customers for the 2024 SOC 2 Type II report from our auditors. Their most updated timing is now [edit>] July 7, 2025.
As previously shared, as soon as we have the report in our hands, we will post it on Conveyor for customer access, so remember to SUBSCRIBE to this page so that you will be notified of that upload. Until then, the existing 2023 SOC 2 documents are still the most current, [edit>] and a new Bridge Letter is released to this portal to cover the delay.
Until then-- stay safe out there.
SAP NetWeaver N/A
HireRight is aware of multiple critical CVEs impacting SAP NetWeaver (CVE-2025-42999 and CVE-2025-31324)-- NetWeaver is not used by HireRight; these CVEs do not apply to our environment.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-31324
& https://nvd.nist.gov/vuln/detail/CVE-2025-42999
Stay safe out there!
Erlang/OTP N/A
HireRight is aware of an Erlang/OTP SSH Vulnerability with a 10.0 critical rating (CVE-2025-32433)- this programming language is not present in the HireRight environment, and so it is not applicable.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-32433
Stay safe out there!
WinRAR CVE-2025-31334
HireRight is aware of WinRAR critical (now med) vulnerability with code execution risk; HireRight systems are patched beyond the impacted versions.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-31334
Stay safe out there!
Ivanti CVE Non-Applicability (Part II)
HireRight is aware of the recent Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457), however, Ivanti is not in use within our environment, making these non-applicable.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-22457
Stay safe out there!
CrushFTP non-use
HireRight is aware of the Critical-rated CVE-2025-31161 impacting CrushFTP v10 before 10.8.4 and v11 before 11.3.1, allowing authentication bypass and takeover of the crushadmin account, however, HireRight does not use CrushFTP in our environment, which renders this CVE N/A.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-31161
Stay safe out there!
Oracle Cloud Attack Non-Applicability
HireRight is aware of the supply chain attack impacting Oracle Cloud Services (https://www.cloudsek.com/blog/the-biggest-supply-chain-hack-of-2025-6m-records-for-sale-exfiltrated-from-oracle-cloud-affecting-over-140k-tenants). <- Link contains an exposure checker.
HireRight is not using Oracle Cloud in our environment, so the attack does not apply to our environment.
Stay safe out there.
SOC 2 Type II Update
HireRight is indeed in the process of updating our existing SOC 2 Type II covering Jan1-Dec31 2024 with our external auditor.
The ETA for that report is May 2025. Until then, the 2023 SOC 2 Type II with Status Letter (fully remediated), and Bridge Letter within the Customer Trust Portal are the most current versions of all three docs. The Portal will be updated as soon as the new versions are ready!
Stay safe out there. :)
N/A Fortinet/ FortiOS CVEs
HireRight is aware of Fortinet's 9.8 (critical) vulnerabilities: CVE-2024-55591 & CVE-2025-24472. Fortinet/ FortiOS is not used in the HireRight environment, so neither applies to our services.
FMI: https://fortiguard.fortinet.com/psirt/FG-IR-24-535
Stay safe out there.
Non-Applicability re: BeyondTrust CVEs
HireRight is aware of "Critical" and "High" rated and known exploited vulnerabilities regarding BeyondTrust CVE-2024-12356 and CVE-2024-12686. Impacted products are not in use in the HireRight environment, so the CVEs are not applicable to HireRight.
For more information, please see the notices
https://nvd.nist.gov/vuln/detail/CVE-2024-12356 and https://nvd.nist.gov/vuln/detail/CVE-2024-12686.
Stay safe out there.
Non-Affiliation with DISA Global Solutions, Inc.
HireRight has received inquiries regarding any affiliation with "DISA Global Solutions, Inc." and we are pleased to assure our customers that there is no HireRight affiliation with this company, nor are they a vendor to HireRight.
FMI: https://www.cybersecuritydive.com/news/DISA-data-breach-affects-33m-people/741112/
Stay safe out there.
2024 SOC 2 Type II
HireRight is indeed in the process of updating our existing SOC 2 Type II covering Jan1-Dec31 2024. The ETA for that report is May 2025. Until then, the 2023 SOC 2 Type II with Status Letter (fully remediated), and Bridge Letter within the Customer Trust Portal are the most current versions of all three docs.
Check back for the new docs in MAY. What's in the portal are always the most current versions of our released attestations.
Cheers!!
Cleo CVE Non-Applicability
HireRight is aware of two "Critical" rated and known exploited vulnerabilities regarding Cleo file-transfer software: CVE-2024-50623 and CVE-2024-55956. HireRight is not using Cleo and so this CVE is not applicable to our service or environment.
For more information, please see notices: https://nvd.nist.gov/vuln/detail/CVE-2024-55956 and https://nvd.nis
Have a lovely holiday season, and stay safe out there.
ServiceNow CVEs
HireRight has received inquiries about the applicability of two critical vulnerabilities (CVE-2024-4879 & CVE-2024-5217) impacting ServiceNow- patching is already in place for these CVEs as confirmed by our SecEng team. FMI on these vulnerabilities, see https://www.upguard.com/blog/servicenow-vulnerabilities.
Stay safe out there.
Inquiries re: Rackspace
HireRight is aware of the supply chain attack on Rackspace. We previously had a business relationship with Rackspace, which ended in Q2 of 2024 when HireRight selected a different vendor at contract end. Rackspace has never had access to our customer data, as our relationship was leasing space in their UK DC only. HireRight is unimpacted by this attack.
FMI: https://www.techradar.com/pro/security/rackspace-internal-systems-hit-by-security-threat
Stay safe out there.
Access Management
As a reminder to our customers, HireRight conducts quarterly access reviews which is the same for our Trust Portal-- for our customers utilizing our portal regularly, this should be a non issue. Otherwise, if inactivity surpassing 90 days results in your access removal, please simply re-request at any time to re-gain read-rights. Our TAT for re-approval is <1 business day.
Stay safe out there.
Ruby SAML Non-Use
HireRight is aware of and has had inquiries regarding Critical CVE-2024-45409- Ruby SAML (Gitlab) Authentication Bypass Vulnerability. Please note that Ruby SAML is not in use within the HireRight environment.
FMI- https://nvd.nist.gov/vuln/detail/CVE-2024-45409
Stay safe out there.
Ivanti CVE Non-Applicability
HireRight is aware of Critical Ivanti Vulnerabilities including CVE-2024-8963 (path traversal) & CVE-2024-21887 (command injection), however, Ivanti is not in use within our environment, making these non-applicable.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2024-21887 and https://nvd.nist.gov/vuln/detail/CVE-2024-8963
Stay safe out there.
Non-applicability of Solarwinds CVE-2024-28986
HireRight is aware of the Critical rated CVE-2024-28986: "SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability." This CVE does not apply to HireRight, as SolarWinds WHD is not used within the HireRight environment.
For more information, please see https://nvd.nist.gov/vuln/detail/CVE-2024-28986
Stay safe out there.
Non-Affiliation with National Public Data
HireRight has received inquiries regarding any affiliation with "National Public Data" and we are pleased to assure our customers that there is no HireRight affiliation with this company, nor are they a vendor to HireRight.
FMI: https://cybersecuritynews.com/national-public-data-hacked/
Stay safe out there.
New Docs Added
HireRight's SOC 2 Type II, SOC 2 Status Letter, and CrowdStrike Impact Letter have been added to the HireRight Customer Trust Portal for our approved customers!
If you have lost access after a period of inactivity, please click "REGAIN ACCESS" from the Portal's main page and we will get you in quickly!
OpenSSH CVE-2024-6387 Non Applicability
HireRight is aware of the OpenSSH Vulnerability from July 2024 (CVE-2024-6387)- HireRight is not affected by this vulnerability, we don't use affected versions of OpenSSH and as a part of compensating controls from any future findings we are not allowing external connections to SSH, at the same time we patch our systems monthly.
FMI visit https://nvd.nist.gov/vuln/detail/CVE-2024-6387
Stay safe out there.
CrowdStrike Impact Update 19JUL24 8:40am EDT
From CrowdStrike: "CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, and isolated and a fix has been deployed. We refer customers to the support portal for the latest updates[...]."
As of this morning, some HireRight operations are impacted, however data remains secure.
MOVEit CVE-2024-5806 Non Applicability
HireRight is aware of the MOVEit Transfer Critical Security Alert Bulletin from June 2024 (CVE-2024-5806)-- HireRight does not utilize MoveIt within our environment.
FMI visit https://www.cisa.gov/news-events/alerts/2024/06/28/progress-software-releases-security-bulletin-moveit-transfer
Stay safe out there.
SOC 2 Delay Letter
Thank you for your continued patience as you await HireRight’s new SOC 2 Type II. Its issuance from our auditor has been delayed by the inclusion of the US DMF certification, which is required
every three years (learn more here: https://www.a-lign.com/articles/blog-what-is-death-masterfile-certification). Our new ETA is MID JULY. As soon as it is available it will be posted here.
We've released a letter FMI: https://trust.hireright.com/d/hire-rights-soc-2-type-ii-delay-letter-may-2024/C8YC8X
Snowflake Vuln Inquiries
HireRight is aware of a vulnerability in which Snowflake is being utilized by threat actors to gain unauthorized access to environments where there is no 2FA. HireRight is unimpacted by this vulnerability as confirmed by InfoSec Engineers. Access to the HireRight environment requires entry via controlled VPN with 2FA. 24/7 monitoring tools and teams are in place.
FMI: https://www.databreachtoday.com/snowflake-clients-targeted-credential-attacks-a-25394
Stay safe out there!
Non Use of National Public Data (US Company)
HireRight is aware of a data breach surrounding US company National Public Data out of Florida (USA). There is confirmation of the non-use of this company from the SVP of Operations and HireRight TPRM.
National Public Data (NPD) out of Florida is NOT a HireRight Vendor. HireRight is unimpacted by their ongoing security event.
Thank you for your attention to this matter- stay safe.
Cisco ASA Non Applicabilty
HireRight is aware of two vulnerabilities relating to Cisco Adaptive Security Appliance (ASA): CVE-2024-20359 & CVE-2024-20353. Cisco ASA is not in place in the HireRight environment; our solution in place is Palo Alto. FMI: https://www.cyber.gc.ca/en/news-events/cyber-activity-impacting-cisco-asa-vpns
Stay safe out there!
SOC 2 Type II Status Update
HireRight's SOC 2 Type II still has an ETA of end-May 2024!
Each year, our InfoSec Audit team and external auditors work together to do an in-depth analysis of the environment with the report always released in mid/end Q2. For your consideration while you wait, we have a Bridge Letter released Feb 2024 and our new Global ISO 27001/ 27701 Certificates available in the Documents section.
To be alerted as soon as the new SOC 2 Type II is available, please SUBSCRIBE to this page!
Non Applicability for Sisense Breach
HireRight is aware of the Sisense breach notification update from CISA (https://www.cisa.gov/news-events/alerts/2024/04/11/compromise-sisense-customer-data). Sisense is not in use within the HireRight environment. Additionally, HireRight ensures that all vendor contracts include a requirement for breach notification should any breach impact our TP/ SC/ Vendor Network.
Stay safe out there.
Palo Alto CVE-2024-3400 Notice
HireRight is aware of threat actors exploiting a critical command injection vulnerability (https://security.paloaltonetworks.com/CVE-2024-3400) in Palo Alto Networks firewalls that allow unauthenticated attackers to execute arbitrary code with root privileges. The vulnerability, with a severity score of 10/10, affects the GlobalProtect feature in PAN-OS versions 10.2, 11.0, and 11.1. HireRight is not using the impacted versions and is therefore not impacted by this vulnerability. Stay safe, all!
Non -Applicability of CVE-2024-23049
HireRight is aware of the Critical rated CVE-2024-23049, in which an issue in Symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component. This CVE does not apply to the HireRight environment, as Symphony is not in use.
Thank you, and stay safe out there!
Update re: CVE-2024-21338 (Windows Kernel)
The InfoSec team is aware of the HIGH (7.8) impact vulnerability involving a Windows Kernel Elevation of Privilege Vulnerability. HireRight's Security Engineering Team has confirmed that servers and devices are patched.
For information on the CVE, please visit https://nvd.nist.gov/vuln/detail/CVE-2024-21338.
Happy patching-- stay safe out there!
ISO/ SOC 2 Update
Hello, valued customers!
HireRight's audit team expects the new 2024 ISO 27001 audit cert within a week +/-. EDIT- this is now available in the Document section for review.
The 2023 SOC 2 Type II report ETA is still mid/end Q2. There is a new Bridge Letter (updated in Feb.) available for your consideration.
Please click "subscribe" on our Portal Page to be instantly updated as soon as both of these are available.
-InfoSec GRC
Non-Applicable ConnectWise CVEs
HireRight is aware of the CVE-2024-1708 (High), where ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability. This vulnerability is not applicable in our environment as HireRight does not use ScreenConnect. Critical CVE-2024-1709 is also not applicable.
Thank you and stay safe out there.
Non-Applicability of FortiOS CVEs
HireRight is aware of multiple CVEs related to FortiOS (CVE-2024-21762, CVE-2024-21762) which have been exploited by a China state-sponsored threat actor to deploy a custom remote access trojan (RAT) dubbed COATHANGER. HireRight is not using FortiOS products within our environment, so the FortiOS CVEs are not applicable in our environment.
Stay safe everyone.
ISO 27001 2024 Cert Coming Soon!
Hello, valued customers! HireRight's audit team is in the final stages of the 2024 ISO 27001 audit process. We understand that customers are ready for the new certificate; the version in the portal is the most current version available. Please click "subscribe" on our Portal Page to get an instant update as soon as the certificate(and/or other documents including the SOC 2 Type II) is updated. Thanks for checking!
Ivanti CVE Non-Applicability
The InfoSec GRC is aware of the vulnerabilities involving Ivanti (ex. CVE-2023-46805 and CVE-2024-21887). These vulnerabilities do not apply to HireRight, as Ivanti products are not in use. HireRight's TPRM Team continues to reach out to vendors to further monitor the situation- please be aware that any impact resulting in a breach is followed by an SLA-level reporting standard of 24 hours to all affected data owners and/or custodians. Stay safe, all!
CVE-2023-27524 Non Applicability
InfoSec has been made aware of a CVE 9.8 Critical Vulnerability – "Apache Superset Insecure Default Initialization of Resource Vulnerability" (CVE-2023-27524) and can confirm that this vulnerability does not apply to the environment as HireRight is not using Apache Superset.
Thank you!
CVE-2023-7024 Non Impact Update
Re CVE: Heap buffer overflow in WebRTC in Google Chrome https://nvd.nist.gov/vuln/detail/CVE-2023-7024 (rated Sev 8.8/10)
Browser versioning is managed/ controlled by the IT department using MDM-- they have already pushed the update beyond impacted versions, rendering this CVE not applicable.
Thank you!
CrushFTP Vulnerability
HireRight is aware of the zero-day CrushFTP Vulnerability (CVE-2023-43177). Security Incident Response & Engineering has confirmed that this is not applicable to HireRight's services or operations, as CrustFTP is not in use in the environment.
Recent CVE Inquiries (10/2023)
HireRight is aware of CVE-2023-44487 which can cause DoS. We have an internal SOC team operating 24/7/365 utilizing a shared SOC dashboard & SIEM software with extensive thread feed, security device logs, and next-gen behavioral and malware-based logs and analytics to continue to monitor and protect service C.I.A. Mitigation is also in place: HireRight leverages a defense in depth strategy for information security by utilizing Palo Alto firewall & Silverline WAF to protect against DoS attacks.
Recent CVE Inquiries (8/2023)
HireRight has had a number of inquiries related to CVE-2023-3519- "Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability" (rated critical). Our Lead Security Engineer has confirmed that Citrix (NetScalers) is not in use in the environment; this vulnerability is n/a to HireRight services.
Additionally, HireRight has had a number of inquiries related to CVE-2023-36884-Windows Search Remote Code Execution Vulnerability (rated high), which is now patched on our systems.
Welcome to our Customer Trust Portal!
HireRight's InfoSec GRC Team is very excited to roll out our brand new Customer Trust Portal. For too long we've been exchanging information security data through a long process involving tickets, multiple requests, loads of back-and-forth, and too many delays in getting the information you need about Information Security at HireRight. Now we have it here at your fingertips! SUBSCRIBE to this page to receive updates from HireRight's IS GRC Team directly!
Our Philosophy
At HireRight, we understand the need for diligence, especially given our role in employee/ employment candidate data processing. When it comes to information security, we implement best practices to achieve security in depth by implementing a multi-layered approach to security and by auditing policies and controls to strictly adhere to ISO/IEC 27001 and ISO 27701 globally, as well as SOC 2 Type II for US/ North American audit.
HireRight conducts annual penetration testing via our CREST-approved third party (application and network level testing), and we implement continuous vulnerability scanning to ensure both proactive and defensive vulnerability management.
HireRight continuously and heavily invests in our information security programs to ensure secure log-on mechanisms, RBAC user access control, SSO, internal data and process segmentation, etc., and implements state-of-the-art situational awareness monitoring, anomaly detection, and of course, 24x7x365 response by our security operations team. In support of this goal, we allocate an adequate budget to ensure security-by-design is in place to protect our customers' data and comply with application regulations.
At HireRight, Information Security remains a top priority.
We provide our customers with a single solution that aligns with local laws and regulations while integrating data privacy by design into its architecture.
Two of the key regulatory regimes are the Fair Credit Reporting Act (FCRA) applicable in the United States, and the General Data Protection Regulation (GDPR) applicable in the European Union. For more info about our compliance efforts and privacy policy please visit https://www.hireright.com/legal
InfoSec
GRC Team