Hayes Recruiting Hub

    Trust & Security

    Last updated: April 29, 2026

    Hayes Recruiting Hub is built for regulated, high-stakes hiring in the trucking industry. Driver applications include sensitive personal, medical, and motor-vehicle information; this page explains how we protect it.

    Summary

    Encrypted everywhere

    TLS 1.2+ in transit, AES-256 at rest. Resumes, CDLs, medical cards and signed consents live in private storage with signed-URL access.

    Least-privilege access

    Row-level security on every table. Recruiters see only their client. Carrier admins see only their drivers. Audit log on every PII read.

    FCRA & DOT ready

    Background checks, MVRs, drug screens, and Clearinghouse queries are gated by signed consent — enforced in the database, not just the UI.

    TCPA-safe outreach

    Express written consent capture, STOP/HELP keyword handling, opt-out honored across SMS, email, and AI voice within minutes.

    ISO 9001:2015-aligned QMS

    Controlled documents, nonconformance + CAPA (8D) tracking, internal audit log, and retention policies with legal-hold support.

    Tamper-evident documents

    SHA-256 hash chain on every POD/BOL per load, AI OCR + classification, and legal-hold delete-protection enforced in the database.

    Quality Management (ISO 9001:2015)

    Hayes operates an ISO 9001:2015-aligned Quality Management System covering document control, nonconformance and corrective/preventive action (CAPA), internal audits, management review, and per-record-type retention policies. Every document upload is SHA-256 hashed and chained to the previous document on the same load, producing a tamper-evident record auditors can verify offline. Legal holds are enforced in the database — held documents cannot be deleted, even by an admin, until the hold is formally released.

    1. Infrastructure

    The platform runs on managed cloud infrastructure backed by SOC 2 Type II audited providers (Supabase / AWS us-east region by default). Production data is replicated, backed up daily, and isolated from development environments. Edge functions run in geographically distributed, isolated runtimes.

    2. Data protection

    • In transit: TLS 1.2+ enforced; HSTS on all responses.
    • At rest: AES-256 disk encryption for the database and object storage.
    • Documents: Resumes, CDLs, medical cards, drug-screen and BGC reports are stored in private buckets requiring signed URLs.
    • Backups: Daily encrypted snapshots with point-in-time recovery.
    • Tokens: One-time access tokens for public consent, e-sign, and retention links expire automatically.

    3. Access controls

    We use Postgres Row-Level Security on every table that contains applicant or client data. Role assignments live in a dedicated user_roles table — never on the user record — to prevent privilege escalation. Sensitive PII reads are written to an immutable pii_access_log table.

    • Multi-factor authentication available for all staff accounts.
    • Session tokens rotate; refresh tokens are HttpOnly.
    • Service role keys are never exposed to the browser.
    • Vendor accounts (recruiters, agents) are scoped to a single client.

    4. Compliance & frameworks

    Our control mapping aligns with SOC 2 (Security, Availability, and Confidentiality) and we operate in line with the principles of GDPR and CCPA/CPRA for data subject rights. Customers under HIPAA-adjacent workflows (DOT physical exam handling) can request a Business Associate Addendum.

    5. FCRA & DOT compliance

    Background checks, motor vehicle records, drug & alcohol screenings, and FMCSA Drug & Alcohol Clearinghouse queries cannot be ordered without a corresponding signed consent on file. This is enforced by database triggers (gate_bgc_order, gate_mvr_pull,gate_drug_screen) — not just by the UI — so an order is physically blocked if the disclosure was missed.

    • FCRA disclosure & authorization captured before any consumer report.
    • Pre-adverse and adverse-action workflow with timestamped delivery.
    • Clearinghouse full and limited query consents tracked separately.
    • DOT-compliant electronic signatures with IP, user-agent, and timestamp.

    6. TCPA & messaging

    Drivers must provide express written consent before we send marketing SMS or place AI-assisted outbound calls. STOP, HELP, START, CANCEL, UNSUBSCRIBE, and QUIT keywords are honored automatically and propagate across SMS, email, and voice channels. AI voice calls disclose that the caller is an automated assistant at the start of every call and recording is announced where required by state law.

    7. Sub-processors

    We use a small set of vetted sub-processors to deliver email (transactional and marketing), SMS, voice, background screening, and cloud infrastructure. The current list is maintained in our Privacy Policy and updated as it changes. Customers are notified of material sub-processor changes.

    8. Incident response

    We maintain an incident response plan with on-call rotation, communication templates, and post-mortem requirements. In the event of a security incident affecting customer data, impacted customers are notified without undue delay and in accordance with applicable state breach notification laws.

    9. Responsible disclosure

    If you believe you have found a security vulnerability, please report it to security@hayesrecruitinghub.com with steps to reproduce. We commit to acknowledging valid reports within two business days, fixing confirmed issues promptly, and crediting researchers who follow responsible disclosure.

    10. Contact

    Security questions, SOC 2 report requests, BAA requests, and sub-processor lists: security@hayesrecruitinghub.com. Privacy requests: privacy@hayesrecruitinghub.com.


    This document is a comprehensive starting draft prepared from current federal and state law as of the "last updated" date above. It is not a substitute for legal advice. If you are an enterprise customer, your signed master agreement controls over this online version. Please have qualified counsel review and confirm jurisdiction-specific edits and the corporate / registered-agent address placeholders before launch.