generated: '2026-09-13'
method: searched
source: >-
https://www.employinc.com/security-exhibit/, https://www.employinc.com/legal/,
https://www.employinc.com/responsible-ai/,
https://trust.app.holisticai.io/public/nyc-bias-audit/org_01KJQ6J4PPV6486JHT73V975QB/1c98fa3f-8c19-4759-9e33-f8a649cc5bb6,
plus the contracts in openapi/ — all fetched 2026-09-13
name: Employ Inc conformance and compliance
description: >-
Standards and regulatory regimes Employ, Inc. claims in its own published documents, and the
technical conformance its contracts actually declare. Claims and contract evidence are kept apart
on purpose: one is a legal commitment, the other is something an agent can verify.
conformance:
- id: soc2
conforms: true
evidence: >-
https://www.employinc.com/security-exhibit/ section 1.2 Certification — "During the term of the
Agreement, Employ shall maintain AICPA SOC2 certification or equivalent as well as maintain a
lawful transfer mechanism for export of personal data out of the European Union."
kind: contractual-commitment
note: >-
A contractual commitment to MAINTAIN SOC 2, not a published report or a dated audit letter. No
report, period covered or auditor is named anywhere public, and there is no trust center to
request one from.
- id: gdpr
conforms: true
evidence: >-
https://www.employinc.com/dpa/ (GDPR Data Processing Addendum) and a pre-signed DPA at
https://www.employinc.com/wp-content/uploads/2023/11/Employ-Inc-DPA-Presigned.pdf; the Security
Exhibit commits to a lawful EU personal-data transfer mechanism.
kind: published-policy
- id: ccpa-cpra
conforms: true
evidence: >-
https://www.employinc.com/cpra-data-processing-addendum/ plus brand-specific CPRA DPAs for
JazzHR, Lever and Jobvite linked from https://www.employinc.com/legal/.
kind: published-policy
- id: nyc-local-law-144
conforms: true
evidence: >-
Independent AI bias audit results published at
https://trust.app.holisticai.io/public/nyc-bias-audit/org_01KJQ6J4PPV6486JHT73V975QB/1c98fa3f-8c19-4759-9e33-f8a649cc5bb6,
linked from https://www.employinc.com/legal/ as "AI Bias Audit Results".
kind: third-party-audit
verified: link-only
note: >-
This is the domain-standard signal that matters most for an automated-employment-decision-tool
vendor. New York City Local Law 144 requires an annual independent bias audit of any AEDT used
to screen candidates, with a summary of results published. Employ publishes such a link, on its
own legal page, pointing at Holistic AI as the independent auditor. VERIFIED TO THE LINK ONLY:
the target returned HTTP 200 on 2026-09-13 but the body is a 510-byte JavaScript shell
(
, title "Holistic AI Platform") that renders client-side, so the audit
date, the impact ratios and the selection rates were NOT read. What is established is that
Employ publishes an independent bias-audit link; what the audit concludes is not asserted here.
- id: annual-penetration-testing
conforms: true
evidence: >-
https://www.employinc.com/security-exhibit/ section 1.3 Testing — "Employ will conduct at least
annual third-party security tests on applications and infrastructure used to support the
provision of Services and Support to identify security vulnerabilities. Employ will provide
summary reports of security test reports to Customer upon request."
kind: contractual-commitment
note: Reports are available to customers on request, not published.
- id: rfc8288-web-linking
conforms: true
evidence: >-
Probed 2026-09-13 — https://www.employinc.com/wp-json/wp/v2/posts?per_page=1 returned
'link: ; rel="next"'.
kind: contract-verified
- id: openapi-3
conforms: true
evidence: >-
Two self-describing contracts served by Employ's own host —
https://www.employinc.com/wp-json/tribe/events/v1/doc (OpenAPI 3.0.0, 14 paths) and
https://www.employinc.com/wp-json/tec/v1/docs (OpenAPI 3.0.4, 7 paths). Both HTTP 200.
kind: contract-verified
- id: rfc9457
conforms: false
evidence: >-
No surface returns application/problem+json. The WordPress surfaces use the WP_Error envelope
(code/message/data.status) and the status API returns no structured error body at all.
- id: oauth2
conforms: false
evidence: >-
No OAuth surface. /.well-known/openid-configuration and /.well-known/oauth-authorization-server
return 404 on every Employ-controlled host. Authentication is HTTP Basic with a WordPress
application password.
- id: scim
conforms: false
evidence: >-
No SCIM schema URN, no /scim endpoint and no provisioning surface on any employinc.com host.
Recorded because SCIM is the identity-provisioning standard an HR-technology buyer would look
for; where it exists in this group it is implemented per ATS brand, not at the holding company.
- id: hr-open-standards
conforms: false
evidence: >-
No HR Open Standards (HR-XML) message types, no HROS JSON schemas and no reference to the
standard anywhere on employinc.com or in any of the four contracts.
note: >-
Reward-only check, recorded as a measured absence rather than a penalty. The recruiting sector's
interoperability standards — HR Open Standards for candidate and requisition exchange, and
schema.org/JobPosting for job distribution — are the ones worth probing for an ATS group, and
neither appears at the Employ holding-company level.
- id: schema-org-jobposting
conforms: false
evidence: >-
employinc.com is a corporate marketing site and publishes no job feed of its own; the careers
surface at careers.employinc.com sits behind a Cloudflare interstitial (HTTP 403 to a
non-browser client) and could not be inspected.
domain_standard:
market: applicant tracking / automated employment decision tools
standard: NYC Local Law 144 independent AI bias audit
declared: true
evidence: >-
https://trust.app.holisticai.io/public/nyc-bias-audit/org_01KJQ6J4PPV6486JHT73V975QB/1c98fa3f-8c19-4759-9e33-f8a649cc5bb6
(HTTP 200, JS-rendered — link verified, contents not read), linked as "AI Bias Audit Results"
from https://www.employinc.com/legal/ (HTTP 200).
note: >-
Employ also publishes a governance narrative at https://www.employinc.com/responsible-ai/ stating
its AI is built on IBM watsonx with independent bias audits, and an AI-specific terms of service
at https://www.employinc.com/ai-terms-of-service/. The audit link is the part that is externally
verifiable.
certifications_published:
- SOC 2 (committed in the Security Exhibit; no report published)
gaps:
- No trust center. trust.employinc.com does not resolve and /trust/ returns 404.
- No ISO 27001, ISO 42001, HIPAA, PCI DSS or FedRAMP claim anywhere public.
- No published SOC 2 report, audit period or auditor name.
- >-
llms.txt IS published at https://www.employinc.com/llms.txt (HTTP 200, 89,688 bytes, generated by
All in One SEO v4.9.1.1, first heading "# Employ") — but 306 of the 311 links inside it point at
http://3mw-dev-employinccom.pantheonsite.io/, the Pantheon DEVELOPMENT environment, not at
www.employinc.com. Only 5 links use the production domain. The dev host is live and returns HTTP
200 for those paths, so an agent following the file lands on a public staging copy of the site
over plain HTTP. The file is real and is Employ's own; its contents send agents to the wrong host.
Probed 2026-09-13.