Built to pass the review before it starts.

Reena is ISO/IEC 27001 certified, handles data to GDPR and PDPA standards, and runs on Microsoft Azure with regional hosting, single sign-on, granular permissions and a full audit trail. Hiring data is sensitive; the platform is built like it knows that.

ISO
27001
Certified ISO/IEC 27001 information security
GDPRGDPR compliant data handling
PDPASingapore & Sri Lanka PDPA, UAE data law
Built on Enterprise Azure AI

The claims your auditors can check themselves.

Certification is the difference between a security page and a security posture: ISO/IEC 27001 means an external auditor has examined how we build, run and protect the platform, and keeps examining it.

StandardWhat it coversStatus
ISO/IEC 27001Information security management across the organisation and the platform, independently auditedCertified · view certificate
GDPRLawful processing, data-subject rights, deletion workflows and consent records for candidates in Europe and beyondCompliant data handling
PDPAPersonal data protection for Singapore and Sri Lanka, alongside UAE data law for Gulf operationsCompliant data handling
Microsoft AzureEnterprise cloud infrastructure with monitored uptime, encryption at rest and in transit, and regional deploymentsProduction platform

Enterprise controls, on by design.

The controls IT teams ask about in procurement are not enterprise extras bolted on later: they are how Reena works for every client.

SSO

Single sign-on

Google Workspace, Microsoft Entra ID or any OpenID Connect provider. Your team signs in with the work account they already use, governed by your identity policy.

RBAC

Roles & permissions

Granular, customisable roles decide who sees and does what, down to programmes and departments. Hiring managers see their roles, not your whole pipeline.

LOGS

Audit trails

Activity is recorded across applications, documents, e-signatures and settings, so every change has an author, a time and a history you can produce on request.

DATA

Data protection

Encryption in transit and at rest, AES-256 for connected calendar credentials, signed webhooks, rate limiting, and calendar access limited to free/busy status only.

Responsible AI · our pledge

AI in hiring is a responsibility
before it is a feature.

Hiring decisions affect people's lives, so a human stays in control of every one. This is the commitment Reena is built on, and the reason our clients can defend their process to candidates, hiring committees and regulators.

01

You set the rules.

Reena screens, interviews and progresses candidates on requirements your team defines. It does not improvise, and it applies the same rules to the first application and the ten-thousandth.

02

Every decision is shown.

Each recommendation records the signals that lifted a candidate and the ones that held them back. There is no score without reasoning attached.

03

You make the call.

Every AI recommendation can be reviewed, adjusted and overridden by your recruiters. No candidate is rejected by a machine alone.

04

Your data trains no one.

AI runs on Microsoft's enterprise Azure AI services. Candidate data is processed to evaluate candidates for you, not to train public models.

05

Ready for what regulators ask next.

Oversight, explainability and the right to override are the exact properties AI regulation is converging on. Teams on Reena are already operating that way.

AI at the scale of a thousand applications, under the control of one recruiter's judgement.

Bring your IT and security teams to the first call. The certificate is public, the DPA is ready, and the questions they will ask are answered in this page's language, not in ours.
Legal documents: Privacy · DPA · AI Transparency · AUP

Frequently Asked Questions

On Microsoft Azure, in regional deployments held to GDPR and PDPA standards. Enterprise agreements can pin your data to a specific region, so candidate records stay where your regulators and your policies expect them to be.
No. Reena runs on Microsoft's enterprise Azure AI services, and your candidate data is not used to train public models. AI is used to read and score against the requirements you set, with the reasoning recorded and a human holding the final decision.
Deletion workflows are built into the platform, so a candidate's request to be forgotten is executed and recorded rather than handled over email. Consent is versioned: when your policies change, candidates are asked again, and the record shows who agreed to what and when.
Single sign-on with the work accounts your team already uses: Google Workspace, Microsoft Entra ID, or any identity provider that speaks OpenID Connect. Access is governed by granular roles and permissions your admins control.
Free and busy status only, never event titles, attendees or descriptions. Calendar tokens are encrypted with AES-256, and disconnecting an account revokes access immediately.
Yes. The ISO/IEC 27001 certificate is public, and our data processing agreement, subprocessor details and security documentation are available for your review during procurement. Bring your IT and security teams to the demo: the fastest review is the one done early.

The rollout that doesn't
get stuck in review.