Your data. Your team. Your call.

    Laidback lives inside your team's chat and touches sensitive hiring data. We treat that like a responsibility, not a feature. Here's exactly what that looks like today, and what's shipping next.

    $100 of credits on us. No card required.

    I work for you. Just you.

    Each workspace is a hard technical boundary. Your briefs, your candidates, your messages, your learned hiring bar. None of it ever crosses over to another team, another company, or a shared model. When you disconnect me from a tool, I stop reading from it immediately. When you close your workspace, I forget.

    Chat in, hiring work out. Nothing sideways.

    Slack, Teams or WhatsAppYou brief me where you already talk
    Your Laidback workspaceIsolated storage, your context only
    Your ATSApproved work written straight back

    Nothing is stored beyond what you approve. Data flows through your workspace and back into your ATS, never sideways to another company.

    The guarantees you get on day one.

    Encryption in transit and at rest

    TLS for everything moving between you and Laidback. Industry-standard encryption for everything stored on our side.

    Single-tenant Google Cloud storage

    Every customer's data lives in its own Google Cloud environment, logically separate. No shared databases, no cross-tenant access.

    Per-user access control

    Every teammate has their own account, their own permissions, and their own connections. Nothing is shared unless you decide to share it.

    No shared model training

    Your briefs, messages and candidate context are never used to train models that other customers see. Ever.

    Data retention you can reason about

    Workspace content is deleted or anonymized within 30 days of closing your workspace, and candidate data ages out after 24 months of inactivity.

    Candidate data rights, respected

    Candidates can request access, correction, deletion or a human review of any automated assessment at any time.

    GDPR and EU data residency

    We act as a processor under GDPR, sign DPAs, and keep EU/EEA workspace data in EU/EEA Google Cloud regions by default.

    Incident response with a clock on it

    We monitor production continuously. If a breach affects your data, we notify your workspace admin within 72 hours.

    Disconnect kills access instantly

    Revoke a connection and Laidback stops pulling from it immediately. No lingering tokens, no background jobs.

    GDPR processor
    DPAs on file
    EU/EEA residency by default
    SOC 2 guarded integration layer

    What we're shipping next.

    We're honest about what's live and what's next. These are our top priorities alongside stability, and we're shipping them as fast as we can.

    Per-user OAuth scoping

    Fine-grained control over who can use which connection. Let Tom send outreach through your Gmail without giving him the keys.

    Role-based access controls

    Define what each teammate can see, share and act on inside your workspace.

    Configurable auto-purge

    Set retention windows for messages, candidates and connected-tool data once, and forget.

    Own SOC 2 Type II & ISO 27001

    Formal company-level certification is on our roadmap. Our integration layer already sits inside a SOC 2 guarded architecture.

    Sensitive data detection

    Automatic detection and masking of sensitive content before it reaches any model.

    Clean workspace, one click

    Wipe Laidback's learned context while keeping your account and connections intact.

    Frequently asked questions.

    Yes. All data in transit is encrypted via TLS. Data at rest is encrypted using industry-standard AES-256. Access to production systems is restricted to a small group of engineers using SSO and hardware keys.

    Absolutely not. Each workspace is completely isolated from every other workspace. Your data is never shared with, or accessible to, other organizations. The workspace boundary is a hard technical boundary, not just a policy.

    No. Your briefs, messages, calibration and connected-tool data are never used to train shared models that other customers see. Laidback learns your hiring bar inside your workspace only.

    Laidback stops pulling new data from that source immediately. Because Laidback synthesizes information across your workspace (notes, summaries, learned context), some insights derived from that integration may persist in its working memory. If you need a full reset, request a Clean Workspace and we wipe stored context while keeping your account intact.

    Every teammate signs in with their own account. They only see the connections and channels their role gives them access to. Fine-grained role-based access controls and per-user OAuth scoping are shipping around launch, so you can, for example, let a teammate send outreach through your Gmail without ever giving them the credentials.

    Formal certification is on our roadmap. We operate to the same security standards today: encryption, workspace isolation, least-privilege access, audit logging, and vendor DPAs. We're happy to walk your security team through our controls.

    On Google Cloud, in a single-tenant environment that is isolated for your workspace. Your data is never stored in a shared database with other customers. We host in Google Cloud regions in the United States and the European Union, with EU/EEA data staying in EU/EEA regions by default. For any international transfers we rely on Standard Contractual Clauses and GDPR safeguards.

    Yes. We act as a processor under GDPR, sign DPAs, support data subject requests, and keep EU/EEA workspace data in EU/EEA Google Cloud regions. For AI bias, Laidback is designed as a drafting and research assistant, not a decision-maker. We do not auto-reject or auto-hire candidates. Every outreach, evaluation note and ATS writeback requires a human review and approval step, so your team stays in control of hiring decisions and fairness.

    Yes. You can request an export in a machine-readable format or a full deletion at any time by emailing privacy@laidback.so. We respond within 30 days.

    We monitor production continuously with real-time alerts and audit logs. If a breach affects your data, we notify the admin of your workspace within 72 hours with what happened, what we did about it, and what you should do.

    Security or privacy question we didn't cover? Email security@laidback.so.

    Get $100 of credits and try it on the roles you have open today.

    $100 of credits on us. No card required.