Skip to main content

Security and compliance

Happydance is an enterprise careers website platform. We sit between your ATS and your candidates, which means your information security, procurement and data protection teams will want evidence rather than reassurance.

This page is that evidence, in one place. If you need something that is not here, ask us and we will tell you either way.

What certifications does Happydance hold?

Certification Certifying body Scope Valid
SOC 2 Type 2 A-LIGN Security and Availability Trust Services Criteria Audit period 1 July to 31 December 2025, report issued 15 April 2026
ISO/IEC 27001:2022 BSI, certificate IS 827210 Our entire SaaS careers website platform, UK and US operations 16 May 2025 to 15 May 2028
Cyber Essentials CyberSmart, under IASME Whole organization 2 December 2025, recertification due 2 December 2026

All 93 ISO 27001 Annex A controls are applicable and implemented, per Statement of Applicability v2. Our certificate can be validated directly with BSI at bsigroup.com/ClientDirectory under certificate number IS 827210.

SOC 2 Type 2 and ISO 27001 are complementary rather than alternatives. ISO 27001 certifies that we run an information security management system to a defined standard. SOC 2 Type 2 tests whether specific controls actually operated over a period of time. SOC 2 produces a report shared under NDA rather than a certificate.

What did the SOC 2 Type 2 audit cover?

A-LIGN audited Happydance from 1 July to 31 December 2025 against two of the five Trust Services Criteria defined by the American Institute of Certified Public Accountants.

Security. That systems and data within the platform are protected against unauthorized access, both physical and logical. Access controls, encryption, network security, vulnerability management, incident response and change management.

Availability. That the platform is available for operation and use as committed. Capacity monitoring, backup and recovery, disaster recovery planning, and business continuity.

A-LIGN issued a clean opinion with no exceptions noted across every control tested, and no significant system changes or incidents during the audit period.

Is the certification kept current?

Yes, and it is independently checked rather than self-declared. Our ISO 27001 certification runs on a three-year programme with BSI, with surveillance audits in between. No non-conformities were raised at the most recent surveillance assessment.

Do you penetration test the platform?

Yes, on two tracks.

An annual manual penetration test by Cyber Defence UK. Expert-led, conducted to the CREST Defensible Penetration Test standard in line with NCSC guidance, by testers holding OSCP, CREST or TIGER qualifications. The most recent engagement ran in May 2026 against the production platform and the CMS, with a retest in June 2026 confirming remediation. There are no outstanding findings. The next test is due in May 2027.

Continuous automated scanning. AppCheck-NG runs on a scheduled bi-annual basis, plus additional scans triggered at feature release as part of our software development lifecycle. Automated scanning complements the annual manual test rather than replacing it.

We also run static analysis on every commit through GitHub Advanced Security, and Dependabot for dependency vulnerabilities.

Full penetration test reports are available to customers and prospects under NDA. We do not publish findings.

Where is the platform hosted?

On Microsoft Azure, in three regions:

Region Used for
UK South UK production
Germany West Central EMEA production
Central US US production

All public traffic routes through Cloudflare for WAF, DDoS protection, TLS termination, rate limiting and bot management. The application runs on Windows Server virtual machines. Azure is named as our subservice organization in the SOC 2 Type 2 report.

How is data protected?

Encryption. AES-256 at rest, TLS 1.2 or higher in transit. Service-to-service authentication uses OAuth 2.0 and JWT.

Network separation. Network Security Groups enforce default-deny on all inbound traffic, behind the Cloudflare edge.

Non-production environments use sanitized or synthetic data. There is no live candidate data in our development or UAT environments.

Access control. Least-privilege role-based access throughout, with privileged accounts held separately from standard accounts. Quarterly access reviews. MFA enforced on all administrative and privileged access, and on VPN. Audit logs retained for 180 days.

For your own team, Happydance supports single sign-on via OpenID Connect, with SCIM provisioning where your identity provider supports it.

What are your recovery commitments?

Azure Site Recovery replicates virtual machine state across regions, and SQL Failover Groups provide automatic database promotion. Disaster recovery is tested twice a year, most recently in June 2026.

Our contractual recovery commitments operate on two tiers:

Tier Covers RTO RPO
Tier 1 Customer careers websites, virtual servers, SQL databases 12 hours 12 hours
Tier 2 Back-office CMS 24 hours 4 hours

What availability do you commit to?

Our Service Level Agreement guarantees 99.9% availability, calculated monthly by UpTime Robot. We commit to the careers website being available 24 hours a day, 7 days a week, outside scheduled maintenance, for which you are notified at least 24 hours in advance.

If uptime falls below the level that applies to your support package in any calendar month, you can claim a service credit of 10% of that month's subscription fees:

Support package Credits claimable below
Elite Support 99.9%
Standard Support 95.0%

Credits are applied against future payments and are the sole remedy for a failure to meet the availability commitment. You receive an uptime report every quarter.

Downtime excludes scheduled maintenance and defined exclusion events. Unavailability of the CMS or back office that does not affect candidate access to your careers website does not count as downtime. Full definitions, exclusions and the credit calculation are set out in the Service Level Agreement.

Live and historic platform status is published at status.happydance.love, where you can subscribe to incident notifications.

Where does candidate data go?

Happydance pulls job listings and screening questions from your ATS by API, presents them through your branded careers website, and transmits completed applications back. Applicant data is not stored beyond that transit. All long-term candidate and job data lives in your ATS, governed by your existing retention and access controls.

There is one documented exception. Where the Job Alerts feature is enabled, candidate email addresses for alert subscriptions are stored in Azure SQL, as set out in section 4.2(b) of our Data Processing Agreement.

The personal data we hold directly is back-office user account data for your administrators, retained for three years after last interaction.

Who are your sub-processors?

We have twelve, and Data Processing Agreements are in place with all of them. The principal ones are Microsoft Azure for hosting and search, Cloudflare for WAF and CDN, Google for analytics, Vercel and AWS for the customer portal, SendGrid and Twilio for transactional email and job alerts, Atlassian for support ticketing, UptimeRobot and New Relic for monitoring, and OpenAI and Groq for AI inference.

The canonical, current list is published in the legal document library, which also holds our Data Processing Agreement, Platform Terms of Use, Service Level Agreement and Fair Use Policy.

Cross-border transfers to the US are handled under Standard Contractual Clauses for both UK and EU GDPR.

How do you use AI, and is our data used to train it?

No. Customer and candidate data is never used to train AI models.

AI features run in stateless, inference-only mode, with no prompt logging at the AI layer and no memory between sessions. Inference is provided by OpenAI and Groq as sub-processors under contractual and security controls. Job data is indexed through Azure AI Search, synced from your ATS.

Where AI is candidate-facing or editor-facing, it is assistive rather than autonomous, and a person reviews output before anything is published.

How do you handle incidents?

Incident response follows NIST SP 800-61, with a defined Cyber Incident Response Team and a documented plan reviewed and tested at least annually.

We are registered with the ICO under ZB718357, and our breach notification process meets the 72-hour requirement under UK and EU GDPR from confirmation of an incident.

Is the platform accessible?

The careers websites you build on Happydance are designed and tested to WCAG 2.1 AA. Our Accessibility Conformance Report records a conformance level of "Supports" against the WCAG 2.1 AA criteria, and the ACR is available on request.

That covers the Happydance platform and the careers websites it produces. Accessibility of the content you publish, and of any third-party scripts or embeds you add to your careers website, remains yours.

How do I get a copy of the SOC 2 report?

The SOC 2 Type 2 report is a restricted-use document, available to customers and prospects under NDA as part of due diligence. Ask your Happydance contact, or request access through our team. We will not ask you to complete a portal or wait on a queue.

Who do I talk to about a security review?

If your security or procurement team needs the SOC 2 report, a completed questionnaire, or answers to something specific, contact us and we will route it to the right person. We would rather answer a hard question early than late.


Frequently asked questions

  • Is Happydance SOC 2 compliant?
    Yes. Happydance holds a SOC 2 Type 2 report, independently audited by A-LIGN, covering the Security and Availability Trust Services Criteria for 1 July to 31 December 2025, with a clean opinion and no exceptions.
  • Is Happydance ISO 27001 certified?
    Yes. Certified to ISO/IEC 27001:2022 by BSI under certificate IS 827210, covering our entire SaaS careers website platform across UK and US operations, valid to 15 May 2028 and validatable at bsigroup.com/ClientDirectory.
  • Do you carry out penetration testing?
    Yes. An annual manual test by Cyber Defence UK to the CREST Defensible Penetration Test standard, most recently in May 2026 with no outstanding findings, plus scheduled and release-triggered automated scanning, static analysis on every commit, and dependency scanning.
  • Where is our data hosted?
    Microsoft Azure, in UK South for UK and EMEA, Germany West Central for the EU, and Central US for the US.
  • Do you store candidate applications?
    No. Applications transit Happydance to your ATS and are not stored beyond that transit. The one exception is Job Alerts, where subscriber email addresses are stored, per section 4.2(b) of our DPA.
  • Is our data encrypted?
    Yes. AES-256 at rest and TLS 1.2 or higher in transit.
  • Is our data used to train AI models?
    No. AI features are stateless and inference-only, with no prompt logging and no memory between sessions, and neither customer nor candidate data is used for training.
  • Does Happydance support SSO?
    Yes, via OpenID Connect, with SCIM provisioning where your identity provider supports it.
  • What are your RTO and RPO?
    Tier 1, covering careers websites, servers and databases, is 12 hours RTO and 12 hours RPO. Tier 2, covering the back-office CMS, is 24 hours RTO and 4 hours RPO. Disaster recovery is tested twice a year.
  • What uptime do you guarantee?
    Our SLA guarantees 99.9% availability, calculated monthly by UpTime Robot. Service credits of 10% of that month's fees are claimable if uptime falls below 99.9% on Elite Support or 95.0% on Standard Support. Live status is at status.happydance.love.
  • Is the Happydance platform accessible?
    The platform and the careers websites built on it are designed and tested to WCAG 2.1 AA. Our Accessibility Conformance Report records a conformance level of "Supports", and is available on request. Content you publish and third-party scripts you add remain your responsibility.
  • Is Happydance GDPR compliant?
    Happydance acts as processor and the customer as controller. We are aligned with GDPR and UK GDPR, hold DPAs with all sub-processors, and handle US transfers under Standard Contractual Clauses. Our DPA and sub-processor list are in the legal document library.
  • Does Happydance hold Cyber Essentials?
    Yes. Certified by CyberSmart under IASME on 2 December 2025, covering the whole organization.

Ready to talk?

Bring us your security questionnaire. Book a demo and we will get your information security team what they need.