HireRight, LLC

HireRight, LLC

Search the Trust Center...
Ctrl +K

HireRight, LLC | Trust Center

Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.

Quick links

Badges

Documents & Knowledge Base FAQs

Announcements

Now Available - HireRight SOC 2 Type II 2026

Hello all,

Thank you for your patience as we waited for the public issuance of our SOC 2 Type II. It is now available for review in HireRight's Trust Portal at trust.hireright.com. We also have provided a separate status report document which contains management responses. These can be found in the "Audit Documentation (HireRight)" folder.

Thank you all for your cooperation and patience.

-HireRight Information Security

Cisco Catalyst SD-WAN - CVE 2026-20127 - N/A

HireRight is aware of Cisco Catalyst SD-WAN - CVE 2026-20127 and related vulnerabilities.
We are happy to share that our Network team confirmed we are not affected by these vulnerabilities: HireRight does not have SD-WAN controllers in our environment.

FMI: https://nvd.nist.gov/vuln/detail/CVE-2026-20127

Stay safe out there!

React CVE - N/A

HireRight is aware of React Servers critical CVE-2025-55182. React servers are not used in the HireRight environment, so the CVE is not applicable for our services.

FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-55182

Stay safe out there!

Grafana CVE N/A

HireRight is aware of Grafana's critical CVE-2025-41115. Grafana is not used in the HireRight environment, so the CVE is N/A.

FMI: https://grafana.com/blog/2025/11/19/grafana-enterprise-security-update-critical-severity-security-fix-for-cve-2025-41115/

Stay safe out there.

Fortinet CVEs N/A

HireRight is aware of Fortinet's critica and high rated vulnerabilities: CVE-2025-58034 & CVE-2025-64446. Fortinet/ FortiOS is not used in the HireRight environment, so neither applies to our services.

FMI: https://www.cve.org/CVERecord?id=CVE-2025-58034 and https://www.cve.org/CVERecord?id=CVE-2025-64446

Stay safe out there.

F5 Vulnerability

We are aware of F5 vulnerability, as a precaution we have updated all F5 devices. There is no impact to client's data as a result of F5 vulnerabilities or the F5 updates. 24/7/365 monitoring by the SOC Team continues. Thank you and stay safe!

Cisco IOS/IOS XE CVE update

Re: Cisco IOS/IOS XE vulnerabilities. Our network engineering team has reviewed the advisories and confirmed again as of this morning that HireRight’s environment remains unimpacted; we have validated that appropriate safeguards are in place for mitigation and are applying vendor-recommended updates as part of our standard patch cycle. No customer data or systems have been affected as a result of Cisco vulnerabilities and we continue to monitor the situation closely and will take any additional actions recommended by Cisco or relevant security authorities.
Ref: https://nvd.nist.gov/vuln/detail/cve-2025-20333 & https://nvd.nist.gov/vuln/detail/CVE-2025-20352
Stay safe out there!

N/A GoAnywhere CVE-2025-10035

HireRight is aware of a critical security flaw (CVE-2025-10035, rated 10.0) related to a secure file transfer product called GoAnywhere which "allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection." HireRight is not using GoAnywhere and this CVE is not applicable.

FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-10035

Stay safe out there!

Cisco IOS/IOS-XE CVEs

We are aware of the CVE-2025-20333 & CVE-2025-20362 relating to Cisco IOS/IOS-XE. As per Cisco any type of workaround is temporary for this bug and to mitigate this bug we have to upgrade our all impacted network devices which is the plan and will require some time. We are currently performing tasks which are part of the temporary workaround to avoid the risk and after that we will plan for a permanent fix. Remember to check out https://trust.hireright.com for further updates on CVEs. Stay safe!

Salesloft Drift Inquiries

HireRight is aware of and has had a number of inquiries regarding Salesloft Drift (Ref: https://trust.salesloft.com/?uid=Drift%2FSalesforce+Security+Update).

HireRight has no current or recent direct relationship or integrations with Salesloft, and thus, is not impacted by this exfiltration event.

Thank you and stay safe out there.

N/A Adobe CVEs

HireRight is aware of Adobe EM Forms CVEs (CVE-2025-54253, CVE-2025-54254) and has confirmed that the impacted product is not used at HireRight, rendering the CVEs not applicable.
FMI: https://helpx.adobe.com/uk/security/products/aem-forms/apsb25-82.html
Stay safe out there.

N/A Netscaler CVEs

HireRight has received some inquiries about Citrix/ Netscaler CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424 (rated 9.2-8.7). HireRight is not using Citrix NetScaler in our environment, and all are not applicable as a result.
FMI: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938
Stay safe out there.

HireRight BCP-DR

UPDATE- now posted*

Hello All,
HireRight is aware that customers are requesting the BCP-DR Exercise report; it's currently with leadership for approval. It will be posted here as soon as we have it ready!
Stay safe out there, and thanks for your patience,
HireRight's InfoSec Team

SharePoint CVE-2025-53770 - No impact on HireRight

HireRight is aware of Critical (9.8) CVE-2025-53770, where Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. FMI: https://www.cve.org/CVERecord?id=CVE-2025-53770
No Impact: We have confirmed that the affected SharePoint Server versions are not present in our environment. All SharePoint services used for business are hosted in Microsoft 365, which is not affected.

Preventive Measures: As a precaution, we have implemented custom detection rules in our endpoint protection platform to identify and prevent exploitation patterns (e.g., ToolShell-related activity) in our environment.

Remediation Status: No remediation is required, as the vulnerable software is not present in our environment.

Stay safe!

SOC 2 Type II Released

Hello all,
Thank you for your patience as we waited for the delivery of our SOC 2 Type II. It is now available for review in HireRight's Trust Portal. Managerial responses are attached at the end of this document as opposed to being provided separately as was the case previously.
Stay safe out there (and happy reading)!

Microsoft CVE-2025-53770

HireRight is aware of Critical (9.8) CVE-2025-53770, where Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. This CVE does not apply to HireRight's environment; impacted versions of the software are not in use. FMI: https://www.cve.org/CVERecord?id=CVE-2025-53770

Stay safe out there.

SOC 2 Type II

UPDATE from JULY 16, 2025: THE AUDITOR SAYS SOC 2 TYPE II ETA ONE WEEK

Hello all,
HireRight is anticipating the final receipt of our 2024 SOC 2 Type II this month-- please keep an eye out for an announcement from us here, as we will upload it as soon as we possibly can! We know how many people are anticipating its release.
Thanks for your continued patience,
HireRight's InfoSec GRC Team

Updated Bridge Letter

HireRight's leadership team has released a new SOC 2 Type II Bridge Letter upon cusotmer request-- the new letter covers the time between the dated letter release and the delayed 2024 SOC 2 Type II release, which is now estimated to come in the first week of July, according to our auditor, BDO.

You can access this letter on our Trust Portal by navigating to https://trust.hireright.com/d/updated-6-2-25-bridge-letter-soc-report-delay/Ww1Rlq?lng=en

We continue to thank you for your patience, as we're very much ready to have that report too!

SOC 2 Type II Update

Hello All,

HireRight is waiting as eagerly as most of our customers for the 2024 SOC 2 Type II report from our auditors. Their most updated timing is now [edit>] July 7, 2025.

As previously shared, as soon as we have the report in our hands, we will post it on Conveyor for customer access, so remember to SUBSCRIBE to this page so that you will be notified of that upload. Until then, the existing 2023 SOC 2 documents are still the most current, [edit>] and a new Bridge Letter is released to this portal to cover the delay.

Until then-- stay safe out there.

SAP NetWeaver N/A

HireRight is aware of multiple critical CVEs impacting SAP NetWeaver (CVE-2025-42999 and CVE-2025-31324)-- NetWeaver is not used by HireRight; these CVEs do not apply to our environment.

FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-31324
& https://nvd.nist.gov/vuln/detail/CVE-2025-42999

Stay safe out there!

Erlang/OTP N/A

HireRight is aware of an Erlang/OTP SSH Vulnerability with a 10.0 critical rating (CVE-2025-32433)- this programming language is not present in the HireRight environment, and so it is not applicable.

FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-32433

Stay safe out there!

WinRAR CVE-2025-31334

HireRight is aware of WinRAR critical (now med) vulnerability with code execution risk; HireRight systems are patched beyond the impacted versions.
FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-31334

Stay safe out there!

Ivanti CVE Non-Applicability (Part II)

HireRight is aware of the recent Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457), however, Ivanti is not in use within our environment, making these non-applicable.

FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-22457

Stay safe out there!

CrushFTP non-use

HireRight is aware of the Critical-rated CVE-2025-31161 impacting CrushFTP v10 before 10.8.4 and v11 before 11.3.1, allowing authentication bypass and takeover of the crushadmin account, however, HireRight does not use CrushFTP in our environment, which renders this CVE N/A.

FMI: https://nvd.nist.gov/vuln/detail/CVE-2025-31161

Stay safe out there!

Oracle Cloud Attack Non-Applicability

HireRight is aware of the supply chain attack impacting Oracle Cloud Services (https://www.cloudsek.com/blog/the-biggest-supply-chain-hack-of-2025-6m-records-for-sale-exfiltrated-from-oracle-cloud-affecting-over-140k-tenants). <- Link contains an exposure checker.

HireRight is not using Oracle Cloud in our environment, so the attack does not apply to our environment.

Stay safe out there.

SOC 2 Type II Update

HireRight is indeed in the process of updating our existing SOC 2 Type II covering Jan1-Dec31 2024 with our external auditor.
The ETA for that report is May 2025. Until then, the 2023 SOC 2 Type II with Status Letter (fully remediated), and Bridge Letter within the Customer Trust Portal are the most current versions of all three docs. The Portal will be updated as soon as the new versions are ready!

Stay safe out there. :)

N/A Fortinet/ FortiOS CVEs

HireRight is aware of Fortinet's 9.8 (critical) vulnerabilities: CVE-2024-55591 & CVE-2025-24472. Fortinet/ FortiOS is not used in the HireRight environment, so neither applies to our services.

FMI: https://fortiguard.fortinet.com/psirt/FG-IR-24-535

Stay safe out there.

Non-Applicability re: BeyondTrust CVEs

HireRight is aware of "Critical" and "High" rated and known exploited vulnerabilities regarding BeyondTrust CVE-2024-12356 and CVE-2024-12686. Impacted products are not in use in the HireRight environment, so the CVEs are not applicable to HireRight.

For more information, please see the notices
https://nvd.nist.gov/vuln/detail/CVE-2024-12356 and https://nvd.nist.gov/vuln/detail/CVE-2024-12686.

Stay safe out there.

Non-Affiliation with DISA Global Solutions, Inc.

HireRight has received inquiries regarding any affiliation with "DISA Global Solutions, Inc." and we are pleased to assure our customers that there is no HireRight affiliation with this company, nor are they a vendor to HireRight.

FMI: https://www.cybersecuritydive.com/news/DISA-data-breach-affects-33m-people/741112/

Stay safe out there.

2024 SOC 2 Type II

HireRight is indeed in the process of updating our existing SOC 2 Type II covering Jan1-Dec31 2024. The ETA for that report is May 2025. Until then, the 2023 SOC 2 Type II with Status Letter (fully remediated), and Bridge Letter within the Customer Trust Portal are the most current versions of all three docs.

Check back for the new docs in MAY. What's in the portal are always the most current versions of our released attestations.

Cheers!!

Cleo CVE Non-Applicability

HireRight is aware of two "Critical" rated and known exploited vulnerabilities regarding Cleo file-transfer software: CVE-2024-50623 and CVE-2024-55956. HireRight is not using Cleo and so this CVE is not applicable to our service or environment.

For more information, please see notices: https://nvd.nist.gov/vuln/detail/CVE-2024-55956 and https://nvd.nis

Have a lovely holiday season, and stay safe out there.

ServiceNow CVEs

HireRight has received inquiries about the applicability of two critical vulnerabilities (CVE-2024-4879 & CVE-2024-5217) impacting ServiceNow- patching is already in place for these CVEs as confirmed by our SecEng team. FMI on these vulnerabilities, see https://www.upguard.com/blog/servicenow-vulnerabilities.

Stay safe out there.

Inquiries re: Rackspace

HireRight is aware of the supply chain attack on Rackspace. We previously had a business relationship with Rackspace, which ended in Q2 of 2024 when HireRight selected a different vendor at contract end. Rackspace has never had access to our customer data, as our relationship was leasing space in their UK DC only. HireRight is unimpacted by this attack.

FMI: https://www.techradar.com/pro/security/rackspace-internal-systems-hit-by-security-threat

Stay safe out there.

Access Management

As a reminder to our customers, HireRight conducts quarterly access reviews which is the same for our Trust Portal-- for our customers utilizing our portal regularly, this should be a non issue. Otherwise, if inactivity surpassing 90 days results in your access removal, please simply re-request at any time to re-gain read-rights. Our TAT for re-approval is <1 business day.

Stay safe out there.

Ruby SAML Non-Use

HireRight is aware of and has had inquiries regarding Critical CVE-2024-45409- Ruby SAML (Gitlab) Authentication Bypass Vulnerability. Please note that Ruby SAML is not in use within the HireRight environment.

FMI- https://nvd.nist.gov/vuln/detail/CVE-2024-45409

Stay safe out there.

Ivanti CVE Non-Applicability

HireRight is aware of Critical Ivanti Vulnerabilities including CVE-2024-8963 (path traversal) & CVE-2024-21887 (command injection), however, Ivanti is not in use within our environment, making these non-applicable.

FMI: https://nvd.nist.gov/vuln/detail/CVE-2024-21887 and https://nvd.nist.gov/vuln/detail/CVE-2024-8963

Stay safe out there.

Non-applicability of Solarwinds CVE-2024-28986

HireRight is aware of the Critical rated CVE-2024-28986: "SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability." This CVE does not apply to HireRight, as SolarWinds WHD is not used within the HireRight environment.

For more information, please see https://nvd.nist.gov/vuln/detail/CVE-2024-28986

Stay safe out there.

Non-Affiliation with National Public Data

HireRight has received inquiries regarding any affiliation with "National Public Data" and we are pleased to assure our customers that there is no HireRight affiliation with this company, nor are they a vendor to HireRight.

FMI: https://cybersecuritynews.com/national-public-data-hacked/

Stay safe out there.

New Docs Added

HireRight's SOC 2 Type II, SOC 2 Status Letter, and CrowdStrike Impact Letter have been added to the HireRight Customer Trust Portal for our approved customers!

If you have lost access after a period of inactivity, please click "REGAIN ACCESS" from the Portal's main page and we will get you in quickly!

OpenSSH CVE-2024-6387 Non Applicability

HireRight is aware of the OpenSSH Vulnerability from July 2024 (CVE-2024-6387)- HireRight is not affected by this vulnerability, we don't use affected versions of OpenSSH and as a part of compensating controls from any future findings we are not allowing external connections to SSH, at the same time we patch our systems monthly.

FMI visit https://nvd.nist.gov/vuln/detail/CVE-2024-6387

Stay safe out there.

CrowdStrike Impact Update 19JUL24 8:40am EDT

From CrowdStrike: "CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, and isolated and a fix has been deployed. We refer customers to the support portal for the latest updates[...]."

As of this morning, some HireRight operations are impacted, however data remains secure.

MOVEit CVE-2024-5806 Non Applicability

HireRight is aware of the MOVEit Transfer Critical Security Alert Bulletin from June 2024 (CVE-2024-5806)-- HireRight does not utilize MoveIt within our environment.

FMI visit https://www.cisa.gov/news-events/alerts/2024/06/28/progress-software-releases-security-bulletin-moveit-transfer

Stay safe out there.

SOC 2 Delay Letter

Thank you for your continued patience as you await HireRight’s new SOC 2 Type II. Its issuance from our auditor has been delayed by the inclusion of the US DMF certification, which is required
every three years (learn more here: https://www.a-lign.com/articles/blog-what-is-death-masterfile-certification). Our new ETA is MID JULY. As soon as it is available it will be posted here.

We've released a letter FMI: https://trust.hireright.com/d/hire-rights-soc-2-type-ii-delay-letter-may-2024/C8YC8X

Snowflake Vuln Inquiries

HireRight is aware of a vulnerability in which Snowflake is being utilized by threat actors to gain unauthorized access to environments where there is no 2FA. HireRight is unimpacted by this vulnerability as confirmed by InfoSec Engineers. Access to the HireRight environment requires entry via controlled VPN with 2FA. 24/7 monitoring tools and teams are in place.

FMI: https://www.databreachtoday.com/snowflake-clients-targeted-credential-attacks-a-25394

Stay safe out there!

Non Use of National Public Data (US Company)

HireRight is aware of a data breach surrounding US company National Public Data out of Florida (USA). There is confirmation of the non-use of this company from the SVP of Operations and HireRight TPRM.

National Public Data (NPD) out of Florida is NOT a HireRight Vendor. HireRight is unimpacted by their ongoing security event.

Thank you for your attention to this matter- stay safe.

Cisco ASA Non Applicabilty

HireRight is aware of two vulnerabilities relating to Cisco Adaptive Security Appliance (ASA): CVE-2024-20359 & CVE-2024-20353. Cisco ASA is not in place in the HireRight environment; our solution in place is Palo Alto. FMI: https://www.cyber.gc.ca/en/news-events/cyber-activity-impacting-cisco-asa-vpns

Stay safe out there!

SOC 2 Type II Status Update

HireRight's SOC 2 Type II still has an ETA of end-May 2024!

Each year, our InfoSec Audit team and external auditors work together to do an in-depth analysis of the environment with the report always released in mid/end Q2. For your consideration while you wait, we have a Bridge Letter released Feb 2024 and our new Global ISO 27001/ 27701 Certificates available in the Documents section.

To be alerted as soon as the new SOC 2 Type II is available, please SUBSCRIBE to this page!

Non Applicability for Sisense Breach

HireRight is aware of the Sisense breach notification update from CISA (https://www.cisa.gov/news-events/alerts/2024/04/11/compromise-sisense-customer-data). Sisense is not in use within the HireRight environment. Additionally, HireRight ensures that all vendor contracts include a requirement for breach notification should any breach impact our TP/ SC/ Vendor Network.

Stay safe out there.

Palo Alto CVE-2024-3400 Notice

HireRight is aware of threat actors exploiting a critical command injection vulnerability (https://security.paloaltonetworks.com/CVE-2024-3400) in Palo Alto Networks firewalls that allow unauthenticated attackers to execute arbitrary code with root privileges. The vulnerability, with a severity score of 10/10, affects the GlobalProtect feature in PAN-OS versions 10.2, 11.0, and 11.1. HireRight is not using the impacted versions and is therefore not impacted by this vulnerability. Stay safe, all!

Non -Applicability of CVE-2024-23049

HireRight is aware of the Critical rated CVE-2024-23049, in which an issue in Symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component. This CVE does not apply to the HireRight environment, as Symphony is not in use.

Thank you, and stay safe out there!

Update re: CVE-2024-21338 (Windows Kernel)

The InfoSec team is aware of the HIGH (7.8) impact vulnerability involving a Windows Kernel Elevation of Privilege Vulnerability. HireRight's Security Engineering Team has confirmed that servers and devices are patched.

For information on the CVE, please visit https://nvd.nist.gov/vuln/detail/CVE-2024-21338.

Happy patching-- stay safe out there!

ISO/ SOC 2 Update

Hello, valued customers!

HireRight's audit team expects the new 2024 ISO 27001 audit cert within a week +/-. EDIT- this is now available in the Document section for review.

The 2023 SOC 2 Type II report ETA is still mid/end Q2. There is a new Bridge Letter (updated in Feb.) available for your consideration.

Please click "subscribe" on our Portal Page to be instantly updated as soon as both of these are available.

-InfoSec GRC

Non-Applicable ConnectWise CVEs

HireRight is aware of the CVE-2024-1708 (High), where ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability. This vulnerability is not applicable in our environment as HireRight does not use ScreenConnect. Critical CVE-2024-1709 is also not applicable.

Thank you and stay safe out there.

Non-Applicability of FortiOS CVEs

HireRight is aware of multiple CVEs related to FortiOS (CVE-2024-21762, CVE-2024-21762) which have been exploited by a China state-sponsored threat actor to deploy a custom remote access trojan (RAT) dubbed COATHANGER. HireRight is not using FortiOS products within our environment, so the FortiOS CVEs are not applicable in our environment.

Stay safe everyone.

ISO 27001 2024 Cert Coming Soon!

Hello, valued customers! HireRight's audit team is in the final stages of the 2024 ISO 27001 audit process. We understand that customers are ready for the new certificate; the version in the portal is the most current version available. Please click "subscribe" on our Portal Page to get an instant update as soon as the certificate(and/or other documents including the SOC 2 Type II) is updated. Thanks for checking!

Ivanti CVE Non-Applicability

The InfoSec GRC is aware of the vulnerabilities involving Ivanti (ex. CVE-2023-46805 and CVE-2024-21887). These vulnerabilities do not apply to HireRight, as Ivanti products are not in use. HireRight's TPRM Team continues to reach out to vendors to further monitor the situation- please be aware that any impact resulting in a breach is followed by an SLA-level reporting standard of 24 hours to all affected data owners and/or custodians. Stay safe, all!

CVE-2023-27524 Non Applicability

InfoSec has been made aware of a CVE 9.8 Critical Vulnerability – "Apache Superset Insecure Default Initialization of Resource Vulnerability" (CVE-2023-27524) and can confirm that this vulnerability does not apply to the environment as HireRight is not using Apache Superset.

Thank you!

CVE-2023-7024 Non Impact Update

Re CVE: Heap buffer overflow in WebRTC in Google Chrome https://nvd.nist.gov/vuln/detail/CVE-2023-7024 (rated Sev 8.8/10)

Browser versioning is managed/ controlled by the IT department using MDM-- they have already pushed the update beyond impacted versions, rendering this CVE not applicable.

Thank you!

CrushFTP Vulnerability

HireRight is aware of the zero-day CrushFTP Vulnerability (CVE-2023-43177). Security Incident Response & Engineering has confirmed that this is not applicable to HireRight's services or operations, as CrustFTP is not in use in the environment.

Recent CVE Inquiries (10/2023)

HireRight is aware of CVE-2023-44487 which can cause DoS. We have an internal SOC team operating 24/7/365 utilizing a shared SOC dashboard & SIEM software with extensive thread feed, security device logs, and next-gen behavioral and malware-based logs and analytics to continue to monitor and protect service C.I.A. Mitigation is also in place: HireRight leverages a defense in depth strategy for information security by utilizing Palo Alto firewall & Silverline WAF to protect against DoS attacks.

Recent CVE Inquiries (8/2023)

HireRight has had a number of inquiries related to CVE-2023-3519- "Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability" (rated critical). Our Lead Security Engineer has confirmed that Citrix (NetScalers) is not in use in the environment; this vulnerability is n/a to HireRight services.

Additionally, HireRight has had a number of inquiries related to CVE-2023-36884-Windows Search Remote Code Execution Vulnerability (rated high), which is now patched on our systems.

Welcome to our Customer Trust Portal!

HireRight's InfoSec GRC Team is very excited to roll out our brand new Customer Trust Portal. For too long we've been exchanging information security data through a long process involving tickets, multiple requests, loads of back-and-forth, and too many delays in getting the information you need about Information Security at HireRight. Now we have it here at your fingertips! SUBSCRIBE to this page to receive updates from HireRight's IS GRC Team directly!

Our Philosophy

At HireRight, we understand the need for diligence, especially given our role in employee/ employment candidate data processing. When it comes to information security, we implement best practices to achieve security in depth by implementing a multi-layered approach to security and by auditing policies and controls to strictly adhere to ISO/IEC 27001 and ISO 27701 globally, as well as SOC 2 Type II for US/ North American audit.

HireRight conducts annual penetration testing via our CREST-approved third party (application and network level testing), and we implement continuous vulnerability scanning to ensure both proactive and defensive vulnerability management.

HireRight continuously and heavily invests in our information security programs to ensure secure log-on mechanisms, RBAC user access control, SSO, internal data and process segmentation, etc., and implements state-of-the-art situational awareness monitoring, anomaly detection, and of course, 24x7x365 response by our security operations team. In support of this goal, we allocate an adequate budget to ensure security-by-design is in place to protect our customers' data and comply with application regulations.

At HireRight, Information Security remains a top priority.
We provide our customers with a single solution that aligns with local laws and regulations while integrating data privacy by design into its architecture.
Two of the key regulatory regimes are the Fair Credit Reporting Act (FCRA) applicable in the United States, and the General Data Protection Regulation (GDPR) applicable in the European Union. For more info about our compliance efforts and privacy policy please visit https://www.hireright.com/legal

InfoSec

GRC Team

Coming Soon

Featured Documents

Powered by Conveyor, the first end-to-end customer trust platform.
Learn more