generated: '2026-09-13' method: searched source: >- https://www.employinc.com/security-exhibit/, https://www.employinc.com/legal/, https://www.employinc.com/responsible-ai/, https://trust.app.holisticai.io/public/nyc-bias-audit/org_01KJQ6J4PPV6486JHT73V975QB/1c98fa3f-8c19-4759-9e33-f8a649cc5bb6, plus the contracts in openapi/ — all fetched 2026-09-13 name: Employ Inc conformance and compliance description: >- Standards and regulatory regimes Employ, Inc. claims in its own published documents, and the technical conformance its contracts actually declare. Claims and contract evidence are kept apart on purpose: one is a legal commitment, the other is something an agent can verify. conformance: - id: soc2 conforms: true evidence: >- https://www.employinc.com/security-exhibit/ section 1.2 Certification — "During the term of the Agreement, Employ shall maintain AICPA SOC2 certification or equivalent as well as maintain a lawful transfer mechanism for export of personal data out of the European Union." kind: contractual-commitment note: >- A contractual commitment to MAINTAIN SOC 2, not a published report or a dated audit letter. No report, period covered or auditor is named anywhere public, and there is no trust center to request one from. - id: gdpr conforms: true evidence: >- https://www.employinc.com/dpa/ (GDPR Data Processing Addendum) and a pre-signed DPA at https://www.employinc.com/wp-content/uploads/2023/11/Employ-Inc-DPA-Presigned.pdf; the Security Exhibit commits to a lawful EU personal-data transfer mechanism. kind: published-policy - id: ccpa-cpra conforms: true evidence: >- https://www.employinc.com/cpra-data-processing-addendum/ plus brand-specific CPRA DPAs for JazzHR, Lever and Jobvite linked from https://www.employinc.com/legal/. kind: published-policy - id: nyc-local-law-144 conforms: true evidence: >- Independent AI bias audit results published at https://trust.app.holisticai.io/public/nyc-bias-audit/org_01KJQ6J4PPV6486JHT73V975QB/1c98fa3f-8c19-4759-9e33-f8a649cc5bb6, linked from https://www.employinc.com/legal/ as "AI Bias Audit Results". kind: third-party-audit verified: link-only note: >- This is the domain-standard signal that matters most for an automated-employment-decision-tool vendor. New York City Local Law 144 requires an annual independent bias audit of any AEDT used to screen candidates, with a summary of results published. Employ publishes such a link, on its own legal page, pointing at Holistic AI as the independent auditor. VERIFIED TO THE LINK ONLY: the target returned HTTP 200 on 2026-09-13 but the body is a 510-byte JavaScript shell (
, title "Holistic AI Platform") that renders client-side, so the audit date, the impact ratios and the selection rates were NOT read. What is established is that Employ publishes an independent bias-audit link; what the audit concludes is not asserted here. - id: annual-penetration-testing conforms: true evidence: >- https://www.employinc.com/security-exhibit/ section 1.3 Testing — "Employ will conduct at least annual third-party security tests on applications and infrastructure used to support the provision of Services and Support to identify security vulnerabilities. Employ will provide summary reports of security test reports to Customer upon request." kind: contractual-commitment note: Reports are available to customers on request, not published. - id: rfc8288-web-linking conforms: true evidence: >- Probed 2026-09-13 — https://www.employinc.com/wp-json/wp/v2/posts?per_page=1 returned 'link: ; rel="next"'. kind: contract-verified - id: openapi-3 conforms: true evidence: >- Two self-describing contracts served by Employ's own host — https://www.employinc.com/wp-json/tribe/events/v1/doc (OpenAPI 3.0.0, 14 paths) and https://www.employinc.com/wp-json/tec/v1/docs (OpenAPI 3.0.4, 7 paths). Both HTTP 200. kind: contract-verified - id: rfc9457 conforms: false evidence: >- No surface returns application/problem+json. The WordPress surfaces use the WP_Error envelope (code/message/data.status) and the status API returns no structured error body at all. - id: oauth2 conforms: false evidence: >- No OAuth surface. /.well-known/openid-configuration and /.well-known/oauth-authorization-server return 404 on every Employ-controlled host. Authentication is HTTP Basic with a WordPress application password. - id: scim conforms: false evidence: >- No SCIM schema URN, no /scim endpoint and no provisioning surface on any employinc.com host. Recorded because SCIM is the identity-provisioning standard an HR-technology buyer would look for; where it exists in this group it is implemented per ATS brand, not at the holding company. - id: hr-open-standards conforms: false evidence: >- No HR Open Standards (HR-XML) message types, no HROS JSON schemas and no reference to the standard anywhere on employinc.com or in any of the four contracts. note: >- Reward-only check, recorded as a measured absence rather than a penalty. The recruiting sector's interoperability standards — HR Open Standards for candidate and requisition exchange, and schema.org/JobPosting for job distribution — are the ones worth probing for an ATS group, and neither appears at the Employ holding-company level. - id: schema-org-jobposting conforms: false evidence: >- employinc.com is a corporate marketing site and publishes no job feed of its own; the careers surface at careers.employinc.com sits behind a Cloudflare interstitial (HTTP 403 to a non-browser client) and could not be inspected. domain_standard: market: applicant tracking / automated employment decision tools standard: NYC Local Law 144 independent AI bias audit declared: true evidence: >- https://trust.app.holisticai.io/public/nyc-bias-audit/org_01KJQ6J4PPV6486JHT73V975QB/1c98fa3f-8c19-4759-9e33-f8a649cc5bb6 (HTTP 200, JS-rendered — link verified, contents not read), linked as "AI Bias Audit Results" from https://www.employinc.com/legal/ (HTTP 200). note: >- Employ also publishes a governance narrative at https://www.employinc.com/responsible-ai/ stating its AI is built on IBM watsonx with independent bias audits, and an AI-specific terms of service at https://www.employinc.com/ai-terms-of-service/. The audit link is the part that is externally verifiable. certifications_published: - SOC 2 (committed in the Security Exhibit; no report published) gaps: - No trust center. trust.employinc.com does not resolve and /trust/ returns 404. - No ISO 27001, ISO 42001, HIPAA, PCI DSS or FedRAMP claim anywhere public. - No published SOC 2 report, audit period or auditor name. - >- llms.txt IS published at https://www.employinc.com/llms.txt (HTTP 200, 89,688 bytes, generated by All in One SEO v4.9.1.1, first heading "# Employ") — but 306 of the 311 links inside it point at http://3mw-dev-employinccom.pantheonsite.io/, the Pantheon DEVELOPMENT environment, not at www.employinc.com. Only 5 links use the production domain. The dev host is live and returns HTTP 200 for those paths, so an agent following the file lands on a public staging copy of the site over plain HTTP. The file is real and is Employ's own; its contents send agents to the wrong host. Probed 2026-09-13.