Last updated 3 September 2026
Security and trust
Recruiting data is candidate data, so an AI recruiter has to clear the same review as any other system touching it. This is what Noon holds, how candidate data moves, and exactly what to put in front of your security team.
Only what is audited, nothing implied.
COMPLIANCE
Audited, tested, and documented
01
Noon is SOC 2 Type II compliant, which means our security controls have been independently audited over a period of time rather than at a single point. Noon is also GDPR compliant and processes candidate and user data in line with GDPR requirements. Independent security firms penetration test the Noon application and infrastructure every year, findings are remediated and re-tested, and the summary letter is available under NDA alongside the SOC 2 report. We publish only what we hold: if a framework is not named on this page, we do not claim it. When a security questionnaire asks for a certification we do not hold, your account team will tell you that directly instead of routing you through a sales cycle.
02
Noon supports single sign-on including SAML, so your team authenticates through the identity provider you already govern and offboarding a recruiter in your directory removes their Noon access with it. Enterprise agreements can include data residency options and custom contracting terms. If your review requires specifics beyond what is listed here, ask your account team rather than inferring them from this page.
03
Noon sources candidates across the open web, evaluates them against the criteria your team defines, and runs outreach and scheduling on your behalf. Activity syncs back to your applicant tracking system through an integration layer covering 20+ providers, so your ATS stays the system of record and Noon does not become a second, unreviewed candidate database sitting outside it. Connecting email or an ATS is an explicit, admin-authorized step, not a default.
04
Bring us the questionnaire early. The fastest reviews we see start with four requests: the SOC 2 Type II report under NDA, the latest annual penetration test summary letter, the subprocessor and data-flow description for the integrations you plan to enable, and confirmation of SSO or SAML configuration for your identity provider. Your account team coordinates all four, and a dedicated contact stays with enterprise accounts after the review closes.
Yes. Noon is SOC 2 Type II compliant, meaning the controls have been independently audited over time rather than assessed at a single moment. Enterprise buyers can request the report through their account team as part of a security review.
Yes. Noon is GDPR compliant and processes candidate and user data in accordance with GDPR requirements. Data protection details for individuals are covered in the Noon privacy policy and privacy center.
Yes. Independent third-party security firms penetration test the Noon application and infrastructure annually, and findings are remediated and re-tested. A summary letter of the most recent test is available to enterprise buyers under NDA through their account team.
Yes. Noon supports single sign-on including SAML, so access is governed by your identity provider rather than by individual passwords. For requirements beyond SSO and SAML, ask your account team what is available on your contract rather than assuming.
Noon's SOC 2 Type II report and the latest annual third-party penetration test summary are available to enterprise buyers under NDA, alongside a description of how candidate data flows between Noon, your email, and your applicant tracking system. Request all three through your account team at the start of the review, not the end.
Integrations are admin-authorized. An administrator connects the applicant tracking system or mailbox explicitly, and Noon syncs sourcing, outreach, and scheduling activity back to that system of record. Share the integration list you intend to enable with your account team so the review covers exactly those connections.
Noon publishes SOC 2 Type II and GDPR compliance, annual third-party penetration testing, SSO and SAML support, dedicated enterprise support, and custom contracting with data residency options. Anything not listed on this page is not claimed. If your policy requires a framework beyond these, tell your account team before the technical evaluation so nobody wastes a cycle.
No. Noon integrates with 20+ applicant tracking systems and syncs activity back to the one you already use, so your existing system stays the record of candidate data and the review scope stays narrow.
Noon sells one plan with unlimited sourcing, contacts, agents, and seats, so a security review does not force a plan change and adding reviewers or admins does not change your contract shape. Pricing is quote-based; the pricing page is the official answer.
Book a demo and your account team will send the documentation your reviewers need and confirm what is available on your contract.
