Enterprise Trust & Governance

AI-assisted recruiting,
with humans in control

AI never makes the hiring decision. A candidate's contact details stay hidden until they choose to share them. And every claim here is written to be checked, not just believed.

Trust pillars

Explainable AI by design

Every AI output includes signal names, factor groups, confidence bands, missing signals, and reasoning access. No score ships without explanation.

See AI Confidence

Human-in-the-loop at every gate

A person approves every decision that affects a candidate, a client, or a hire. Every gate requires explicit human approval before the action proceeds, and every gate offers reject or hold with a required reason.

Workspace data isolation

Every workspace has its own isolated data scope. Requisitions, notes, and integration credentials stay inside the workspace that created them. Candidates are only shared when you opt in to the shared talent pool.

EU AI Act Art.14 alignment posture

Kempian is designed to support human oversight requirements for high-risk AI systems as defined under Annex III of the EU AI Act.

Decision audit trail

Every decision is recorded with reviewer identity, timestamp, the AI output on screen at the time, the decision taken, and any override reasoning. Records are append-only: we add to the history, we do not rewrite it.

US-hosted, single-region

Kempian production data is stored and processed in the United States (us-east-1). Your data is not used to train a shared AI model.

US data residencyEncrypted in transit & at restCandidate opt-out honored

We follow GDPR and EU AI Act requirements. We hold no third-party certification yet.

Governance in depth

How Kempian keeps people in control

Six commitments govern every decision the platform touches — each one enforced in the product, not just described here.

Human-in-the-loop

Kempian AI recommends, explains, and prepares. A person approves every decision that affects a candidate, a client, or a hire. The AI never acts on people on its own.

  • AI drafts outreach, shortlists, and evaluations
  • A recruiter reviews and approves before anything is sent or submitted
  • Every gate includes a reject or hold with a required reason
  • Every gate requires explicit human approval before the action proceeds

Explainable AI

No recommendation ships as a black box. Every output names the factors behind it, flags what is missing, and links back to the evidence it was built from.

  • Named factor groups — skills, experience, compliance, location, role signals
  • Missing signals surfaced explicitly, never hidden
  • Source evidence attached to every recommendation
  • Full reasoning available for review

Auditability

Every decision is recorded with reviewer identity, timestamp, the AI output on screen at the time, the decision taken, and any override reasoning. Records are append-only: we add to the history, we do not rewrite it.

  • Reviewer identity and timestamp on every decision
  • The AI output that was on screen at decision time
  • The decision made and any override reasoning
  • Append-only: we add to the history, we do not rewrite it

Workspace data isolation

Every workspace has its own isolated data scope. Requisitions, notes, and integration credentials stay inside the workspace that created them. Candidates are only shared when you opt in to the shared talent pool.

  • Every workspace has its own isolated data scope
  • Requisitions, notes, and records stay in the workspace that created them
  • Integration credentials stay private to a single workspace
  • Candidates are shared only when you opt in to the shared talent pool

Data privacy

Kempian production data is stored and processed in the United States (us-east-1). Your data is not used to train a shared AI model.

  • Kempian production data is stored and processed in the United States (us-east-1)
  • No cross-customer model training
  • Candidate opt-out records enforced before any outreach step
  • Access, export, and deletion controls at the customer level

Healthcare minimum-necessary handling

For healthcare hiring, Kempian is built around minimum-necessary handling — the platform works with only the information a hiring decision requires, and no more.

  • HIPAA-aware data handling practices
  • Only role-relevant information is processed
  • Sensitive data classified and access-scoped
  • Compliance signals kept to what the decision needs

AI suggests. Humans review, adjust, and decide.

Every AI output that could affect a candidate passes through a person before it takes effect. AI never makes the hiring decision.

AI Suggests
Human Reviews
Human Can Edit
Human Approves
Action Taken

Candidate visibility: the Four-State Model

What a recruiter can see depends on how a candidate's data reached Kempian and what they've actually agreed to — not on who's searching. These are separate entry states, not a sequence.

Internal

Full contact details visible

A candidate in a recruiter's own workspace — uploaded, imported, or added by that team. Visible only inside that workspace.

Marketplace

Profile visible, contact hidden

A candidate discoverable on the public marketplace. Their profile is visible; contact details stay hidden until they choose to connect.

AI-Discovered

No personal data shown

A candidate surfaced by AI from public sources. Fully anonymous to the recruiter until the candidate responds to outreach themselves.

Connected

Candidate's own choices apply

Once a candidate connects, their own field-level sharing choices govern what a recruiter sees — and no employer setting can override them.

Internal, Marketplace, and AI-Discovered are separate entry states. Marketplace and AI-Discovered may later become Connected — Internal is its own path, not a step before the others.

Policies & Documents

Every policy and term, in one place

Read our privacy, responsible-AI, security, and platform documents. Enterprise due-diligence documents are available under NDA.

Overview

Responsible AI

Privacy

Security

Platform Standards

Enterprise Due Diligence — under NDA

AI Governance Statement (Full)

On request

Complete AI system inventory, regulatory classification, human oversight, model governance, auditability, and EU AI Act readiness roadmap. Available to enterprise customers under NDA.

Security Overview (Detailed)

On request

Full technical security posture, structured for a vendor security questionnaire. Available to enterprise customers under NDA.

Enterprise customers can request these under a mutual NDA — email trust@kempian.com to begin a security or procurement review.

Supervised AI — clear boundaries

Kempian AI is decision support. Not an autonomous decision-maker. Every action that affects a candidate or client requires explicit human approval — the supervised checkpoint is mandatory, not optional.

See AI Confidence
Calculate AI Confidence scoreAI can do
Surface candidate shortlistAI can do
Flag missing signalsAI can do
Draft outreach messageAI can do
Send outreach without approvalHuman only
Approve a candidate autonomouslyHuman only
Submit to client portalHuman only
Make a hiring decisionHuman only

Governance FAQ

Does Kempian train its AI on my candidate data?

No. Customer data is not used to train or improve the shared AI model. AI insights use supervised AI with prompts constructed from your workflow data. Your data is not retained by the model.

What data does Kempian store and where?

Candidate profiles, requisitions, outreach records, and compliance logs are stored and processed in the United States (us-east-1). Each workspace has its own isolated data scope; candidates are shared between workspaces only where you opt in to the shared talent pool.

How does Kempian handle GDPR data subject rights?

Kempian provides controls for data access, deletion, and export at the customer level. Candidate opt-out records are maintained and enforced before any outreach step. Contact your account team for a data processing agreement.

Can a recruiter override an AI recommendation?

Yes, always. Override capability is a core requirement. Every human review gate includes a reject or hold option with a mandatory reason field for the audit trail.

How is AI Confidence calculated?

Confidence is calculated using supervised AI with named factor groups: skills, experience, compliance, location, and role-specific signals. The rubric is deterministic and documented per role type. It does not infer demographic data.

Need a full governance review?

We provide security posture documentation, data processing agreements, and architecture review calls for enterprise procurement.