Legal
Sub-processors
Written by the Krudo team, not yet reviewed by an external lawyer. It describes what the product does today, measured against the code, and we would rather publish that than a polished document nobody checked.
Third parties that receive data when Krudo runs. Some of them run the service; most of them are services a single check queries, and they appear here because a check that asks a question about an application has to send something to ask it. Each row says what leaves Krudo. Updated with 30 days' notice before any addition; customers with a data processing agreement can object in writing.
This list is not maintained by hand. It is generated from a declaration that the product's own test suite checks against every external address in the source code, so a service cannot be added to Krudo without appearing on this page.
Running the service
Providers that operate Krudo itself. They can hold workspace data and assessment results at rest or in transit.
Your applicant tracking system
Not our sub-processors: your own systems, and your contract with them. Listed because Krudo connects to them on your instruction, and because the direction of travel matters. Krudo reads applications from them and writes a result field back. It sends them no data of its own.
Services a check queries
A check compares what an application states against sources anyone can query. Each row names what leaves Krudo. Some rows only run when your workspace holds that provider's key; where that is the case the row says so.
Off unless you turn them on
Employer and school verification is behind a switch that is off in the shipped configuration (the four FD_ENABLE_ flags in sync-server/scorer.js). Nothing below is contacted until it is on.
The 132 platform probes
One row above covers 132 consumer platforms: streaming services, shops, developer sites, learning sites, social networks. Krudo asks each of them the question their own "forgotten password" form asks, which is whether an address is already registered. That is how a brand-new identity with no history anywhere becomes visible. It runs only in the recruiter's browser, never from our servers, and only when they ask for a full analysis. A quick analysis queries 12 of them.
These are not vendors of ours and there is no contract with them. The e-mail address on the application reaches each one, in the same request an ordinary visitor's browser would make. The full list is in the product's source, one file per platform, and the number above is read from it: adding a platform changes the number on this page.
Links, which are not sub-processors
Krudo also builds links a recruiter can open to check something themselves. Krudo never calls these hosts. Their servers see nothing until someone clicks, and then it is that person's own browser that connects. We list them anyway, because what one click sends is worth knowing.
Questions about this document: legal@krudo.ai · Data requests: privacy@krudo.ai · Security: security@krudo.ai