Security, DPAs and sub-processors
How RemakeCV secures candidate data: encryption, access control, two-factor authentication, an enterprise OpenAI agreement with zero data retention, EU data residency and Data Processing Agreements.
Candidate data is transmitted over encrypted connections and stored in access-controlled cloud infrastructure. AI processing runs on OpenAI under an enterprise agreement with zero data retention — candidate data is not retained by OpenAI after processing and is never used to train models — and EU data residency is available on request. Accounts support two-factor authentication, and a signed Data Processing Agreement is available from support@remakecv.com.
How is candidate data protected?
| Control | Implementation |
|---|---|
| Data in transit | Encrypted over HTTPS/TLS |
| AI processing | OpenAI enterprise agreement — zero data retention, no training on customer data |
| Data residency | EU residency available on request |
| Data at rest | Stored in access-controlled cloud object storage |
| File access | Downloads issued as short-lived signed URLs rather than public links |
| Account access | Password authentication with optional two-factor |
| API access | Bearer API keys, stored hashed, revocable, optionally time-limited |
| Company isolation | Every request is scoped to the authenticated company |
Who processes candidate data?
RemakeCV uses sub-processors for hosting, storage and AI processing. A CV is parsed into structured data by an AI model — that is what makes the formatting work — and the terms under which that happens are the ones your clients will ask about.
AI processing runs on OpenAI under an enterprise agreement. That agreement carries:
- Zero data retention. Candidate data is not stored by OpenAI after your request is processed.
- No training on your data. Customer data is contractually excluded from model training.
- EU data residency, available on request. Email support@remakecv.com and we will configure it for your account.
Alongside that:
- Scoped to purpose. Data is sent only for the specific processing you triggered.
- Company isolation. Every request is scoped to the authenticated company, and one customer's data is never accessible to another.
For the full list of sub-processors and processing locations, email support@remakecv.com — it is maintained alongside the DPA so it stays accurate as infrastructure changes.
If you are completing a client security questionnaire, the three answers most often asked for are here: OpenAI, enterprise agreement, zero data retention and no training, with EU residency available. Request the DPA for the signed version.
If your clients audit your supply chain — common in financial services, public sector and healthcare recruitment — request the DPA and sub-processor list before you need them, not when a questionnaire lands.
What should my agency do?
The controls on your side matter as much as the ones on ours:
Enable two-factor authentication
The single highest-value change you can make. See two-factor authentication.
Remove leavers promptly
A dormant account with access to candidate data is a standing risk. See user roles and permissions.
Set a retention position
Decide deliberately whether CV storage is on, and for how long. See GDPR and data retention.
Rotate API keys
If you use the public API, rotate keys periodically and revoke any key whose holder has left. See authentication.
How do I report a security concern?
Email support@remakecv.com with the details. If you believe you have found a vulnerability, please report it privately rather than publicly, and give us a reasonable window to fix it before disclosure.
Frequently asked questions
- Can I get a signed DPA?
- Yes. Email support@remakecv.com and we will provide a Data Processing Agreement covering sub-processors and the roles of each party.
- Are candidate CVs used to train AI models?
- No. RemakeCV processes CVs through OpenAI under an enterprise agreement with zero data retention: the data is used to produce your formatted output, is not retained by OpenAI afterwards, and is never used to train models.
- Which AI provider does RemakeCV use?
- OpenAI, under an enterprise agreement. The agreement carries zero data retention and excludes training on customer data, and EU data residency is available on request.
- Can candidate data be processed in the EU?
- Yes. EU data residency is available on request — email support@remakecv.com and we will configure it for your account.
- Do you support SSO?
- Two-factor authentication is available on every account as standard. Single sign-on is configured per organisation — email support@remakecv.com with your identity provider and we will set it up.
Related articles
Last updated . Still stuck? Email support@remakecv.com or book a call.