How it works

Four stages, in order. The model only works in the second one.

  1. Intake

    Upload, API and posting folders, plus scheduled mailbox intake once a mailbox provider is connected. Documents are deduplicated by content, so a retry never bills twice.

  2. Extract

    Résumés become skills, each with the line that proves it. Job posts become requirements with a kind and a weight.

  3. Score

    Fit per requirement is computed by arithmetic from those facts, stored once, and returns the same answer every time.

  4. Decide

    A named person decides. Reviews are append-only, outreach needs a second approver, and hire or reject is always a human act.

Why now

Employment selection is classed as high-risk under the EU AI Act, and NYC Local Law 144 requires employers using automated employment decision tools to commission an independent bias audit and notify candidates. A score with no stated reason is difficult to explain under these rules.

On timing

The EU high-risk obligations for employment were due on 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved them to 2 December 2027. It entered into force on 27 July 2026 (Official Journal).

That is a fixed date, not an open-ended delay.

Hiring you can show your work for.

The model reads and cites the evidence. The score is arithmetic. A named person decides.

VoilaHire turns résumés and job posts into structured comparisons. Each requirement's verdict shows the résumé line behind it, or says that none was found, and the same inputs always produce the same score.

One comparison, opened up

Choose a requirement to see the résumé line behind its verdict.

Illustrative résumé excerpt (not a real candidate)

  1. Senior Platform Engineer, payments company, 2022–present
  2. Ran production EKS clusters for 3 years; led the migration off ECS.
  3. Cut deploy time from 40 to 9 minutes across 60 services.
  4. Authored the Terraform module library the platform team standardized on.
  5. Mentored four engineers through on-call certification.

Kubernetes is met by line 2: three years running production EKS clusters.

Scored by arithmetic, not by the model. No single hire or reject verdict is ever produced.

Common questions

Does the AI decide who gets hired?

No. The language model extracts facts and cites the line each came from. Fit is computed by arithmetic. Every hire or reject is recorded as a named person's decision, and no automation setting can change that.

Will VoilaHire make us compliant with the EU AI Act or Local Law 144?

VoilaHire supplies the transparency, evidence and controls those rules ask for, including a decision trace, Annex IV documentation and adverse-impact figures. Whether your use is compliant is your determination, and the system records what you need to support it.

How do you reduce bias?

A per-organization redaction policy removes attributes before scoring, so they cannot influence the result. A catalogue of known proxy patterns is enforced where the score is computed. Self-identification data sits in a separate store the matching module cannot read, and adverse impact is measured there using the four-fifths rule.

Which language models does it use?

The model is configuration: Anthropic, Amazon Bedrock or any OpenAI-compatible endpoint, including a self-hosted open model. A per-organization jurisdiction policy can refuse any model outside your rules, for example US-only or EU-only.

Can we run it ourselves?

Yes. There is first-party Terraform for AWS, a Helm chart for managed Kubernetes, and a single-tenant on-premise install. The on-premise chart has been rehearsed end to end on local Kubernetes. It has not yet been installed outside our own test environment.

Is this available today?

Not yet. VoilaHire is in development and is not commercially available. The product is built and runs end to end in a test environment, and the What's shipped page lists exactly what works today.

A whole hiring operation, not a demo.

Every screen, the API and the agent surface run over the same services and the same permissions. Each capability below is marked with exactly how it ships.

  • Shippedworks out of the box
  • Connected per deploymentneeds a provider or key you supply
  • Stand-inconfigurable placeholder for now

Hiring workflow

From intake to an offer, with a person on every decision.

Decision trace Shipped
Each comparison opens into its full tree: score and confidence, each requirement's verdict and evidence, the competency it maps to, and the human decision on record. Available on screen, over the API and to an agent.
Corporate requirements Shipped
Organization-wide gates such as work authorization or certification, inherited by every posting. A gate not cleared becomes a blocking factor a person confirms, never an automatic rejection.
Recruiting agent Shipped
Works the funnel per posting at the autonomy you set: approve every step, autopilot to the candidate boundary, or full autopilot. It decides nothing; candidates below threshold go to a person for triage.
Candidate messaging Shipped
Templated email through one audited outbox. The first message of each kind is approved by a person. Opted-out candidates are never contacted.
Interview scheduling Shipped
HR publishes availability and candidates book on a private link, with no calendar access required. A live calendar connection is optional Connected per deployment.
Structured interviews Shipped
Interview kits per posting and scorecards against named competencies, so every interviewer assesses the same things. Transcription is Connected per deployment.
Offers Shipped
Draft, approve, issue and track to an answer, with a record of who did what. Approving is always a person's act.
Job distribution Shipped
Publish to a public XML feed and a schema.org job page, the formats Google for Jobs and job aggregators read, with no partner contract needed. LinkedIn, Indeed and other partner boards are Connected per deployment.
Analytics Shipped
Funnel views by measure and breakdown, compared with the previous period, saved and emailed on a schedule. No view ever shows anyone's protected characteristics.
Mobile Shipped
An installable web app for recruiters. Nothing about a person is stored on the phone, and approving from it is the same person-in-the-loop act.

Fairness

Bias controls apply before the score is computed, not after.

Redaction before scoring Shipped
You choose which attributes a comparison may see, and they are removed before scoring. Revealing a name is an audited act with a reason, and it never changes the score.
Bias catalogue Shipped
Known requirement patterns that act as proxies for age, origin or circumstance are refused where the score is computed. Entries that cannot yet be enforced are labeled watch-only on screen.
Self-identification Shipped
Voluntary, and held in a store the matching module cannot read. Adverse impact is measured there using the four-fifths rule; groups too small to stay anonymous are suppressed.

Verification

Real people, real credentials, checked by a person.

Credential catalogue Shipped
Skilled trades and licensed professions in education and healthcare, with the credential each role requires in the US (all fifty states), Canada, the UK, the EU (including Ireland, Germany and France), Australia, New Zealand and India. A cited baseline, not exhaustive, and guidance to verify locally rather than legal advice. Live registry checks are Connected per deployment.
Humanity check Shipped
An interactive proof that a person is behind an application, recorded as a verdict with no biometric kept. Third-party identity and liveness providers are Connected per deployment.
Background checks Shipped
Order, track and adjudicate checks, with adverse action always a person's step. Check providers are Connected per deployment; a labeled simulated provider runs the whole flow until one is connected.

Data and platform

Records you can verify, and data that stays where you put it.

Tamper-evident record Shipped
The event log is a hash chain, sealed periodically and publishable to write-once storage. A verifier reports exactly where a chain diverges.
Data rights Shipped
Erasure removes the person and keeps the fact. Legal holds, retention on your schedule, and a public form for candidates to ask for a human review.
Data export Shipped
A full export of your organization's data runs as a background job and notifies you when it is ready.
Backups proven by restore Shipped
A backup plan is reported as a risk until a test restore has actually succeeded. On the hosted service, a restore cannot bring back a person who was erased.
Languages Shipped
Screens, navigation and error pages are translated, not just the data.
Advisory agent Shipped
Answers product questions from the documentation that ships with the product, names its source, and declines rather than guessing.
Data residency Shipped
A deployment refuses to process data for an organization pinned to another region, including the model call. Multi-region within a single deployment is a Stand-in.

Inside the product

Screens from the running application in mock mode. Every organization, person and score shown is fabricated.

Match report screen for a fabricated candidate against a Staff Engineer posting. It shows a 29% overall score with separate technical, non-technical and soft-skill scores and confidence levels, a notice that every result needs human review, an unmet requirement for 50 years of Java with the candidate's 10.6 years of evidence listed, and a non-technical requirement marked as not assessable from a résumé.
A match report. The unmet requirement shows the evidence that was found, and a requirement that a résumé cannot answer is marked for a person to assess.
Candidate ranking screen for a Staff Engineer posting, listing three fabricated candidates with overall score, confidence and number of gaps, each with an Open report link, under a notice reading: ordering, not deciding.
A ranking orders candidates and says plainly that it does not decide.
A parsed job posting showing its technical requirement, the source text it came from, and a warning that a stated duration of 50 years exceeds any plausible career and should be confirmed with the hiring manager.
A parsed posting. An implausible requirement is flagged for the hiring manager instead of being scored silently.

A number you can't defend is a liability, not a shortlist.

Many AI screening tools produce a score with no reason a recruiter can stand behind and no line to point a candidate to. Tools trained on past hiring outcomes can also learn past bias and hide it inside that number.

Extract, don't decide

The language model extracts structured facts, each with the exact résumé line behind it. Fit is then computed by arithmetic, not by the model, so every score traces back to the words that produced it and comes out identical every time.

You get a fit per requirement, each with its evidence, and never a single hire or no-hire verdict.

What stays human

  • Every hire and every rejection
  • Approving the first message of each kind
  • Adverse action after a background check
  • Approving an offer
  • Revealing a redacted name, with a reason on record

Every decision has a name on it

Append-only reviews
A hiring review is a record. Changing your mind is a newer decision, not an edit, so the history stays.
Two-person outreach
Anyone who can see a candidate can draft outreach; a second person approves it. A decliner's reason is kept.
Notes tied to evidence
Screening-call notes attach to the exact comparison they answer, not a free-floating comment thread.
The hard gate
No automation setting can make an offer or send a rejection. An adverse message is only ever a person's act.

Do more with the same team

A recruiting agent works each posting end to end: parse, match, screen, shortlist and outreach. It asks your preconfigured screening questions and scores answers against a threshold you set per posting.

Candidates below the threshold go to a triage screen for a person to reconsider. Nobody is rejected automatically.

Choose how much it does alone

Recruiting agent autonomy levels
SettingWhat happens
Approve every stepThe agent proposes; a person approves each action.
Autopilot to the candidateRuns on its own up to the point of contacting a candidate, then waits for a person.
Full autopilotRuns the funnel; hire and reject still stay with a person.

Compliance by construction, not as a bolt-on.

Employment selection is high-risk under the EU AI Act, and NYC Local Law 144 requires bias audits and candidate notice. VoilaHire records much of the evidence those rules ask for as part of normal use.

What the system records, and where it helps
CapabilityWhat it gives youRelevant to
Decision traceThe full evidence-and-decision path for every comparison, exportableEU AI Act Annex IV, Local Law 144
Annex IV technical fileTechnical documentation generated from the system itselfEU AI Act
Adverse-impact measurementFour-fifths rule over recorded outcomes, computed inside a walled-off self-identification store. Under Local Law 144 the bias audit itself must be done by an independent auditor; these figures are data for that audit, not a substitute for it.Local Law 144 bias audits; US Uniform Guidelines on Employee Selection Procedures
Obligations registerEach obligation per country marked as automated, kept, ruled out or an open gapMulti-country hiring
Compliance postureWhere your organization stands against a country's rules, as findings rather than a verdictInternal audit
Human oversightHire, reject, adverse action and offer approval are always a named person's actEU AI Act human-oversight duties
Data rightsErasure, legal holds, retention schedules, candidate review requestsGDPR, CCPA/CPRA
Data residency and model jurisdictionData and model calls stay in your region and with models you allowGDPR transfers, public-sector procurement

What we don't claim

VoilaHire gives you transparency, evidence and controls. Whether your use of it complies with a given law is your determination, made with your counsel. The system records what you need to support that determination.

On EU timing

The EU AI Act's employment obligations were scheduled for 2 August 2026. Regulation (EU) 2026/1744, in force since 27 July 2026, moved them to a fixed date of 2 December 2027 (Official Journal).

Trust and security

How VoilaHire protects candidate data, and an honest account of where we are on formal certification.

Encryption
TLS on every network hop and KMS-managed encryption at rest on every store, each checked by an automated test. Field-level column encryption is deliberately not used: it would break deterministic matching without improving protection against realistic threats.
Tenant isolation
Every table is partitioned per organization. A record belonging to another organization returns "not found", so its existence is never confirmed.
Data residency
A deployment refuses to serve or process an organization pinned to another region, including the model call. Today residency is enforced with one deployment per region.
Model jurisdiction
Set a policy such as US-only, EU-only or excluding particular jurisdictions, and any model outside it is refused. You can also run a self-hosted open model, so résumé data need not leave your boundary.
Tamper-evident audit log
Every event is hash-chained to the one before it. Once a chain head is sealed to write-once storage, an edit can be detected even if someone holds the database credentials.
Backups
Reported as a risk until a test restore succeeds. On the hosted service, backup streams carry erasure records or are not shipped, so a restore cannot bring back someone who exercised their right to erasure.
Payment data
Cards on file are processor tokens only. VoilaHire never holds a card number.
Access
One authorization path for people and machines. API keys resolve to service accounts with a defined subset of permissions; agent keys are delegated and expire.

Certifications

VoilaHire does not yet hold SOC 2 or ISO 27001 certification. We will publish our plan and timeline here, and certificates when they are issued.

Reporting a vulnerability

Email info@voilahire.com with "Security report" in the subject. Please don't include exploit details in that first message; we'll arrange a secure channel.

Yours to host, integrate and audit.

A spec-first REST API under /v1, generated SDKs, an MCP surface for agents, and a written promise about what may change under a client.

The contract

  • The version is in the path, so it is visible in every log and pasted command.
  • Additive changes never bump the version. A breaking change means /v2, served alongside /v1.
  • Twelve months' notice before a version stops, announced in response headers, the changelog and by email to active callers.
  • The promise is checked by a build test, not remembered.

SDKs are generated for Java, C# and PHP and verified end to end in CI. Mock mode gives you fixed sample organizations and keys with no model spend.

Response headers to expect

X-RateLimit-Limit: …     # on every response
X-RateLimit-Remaining: …
X-RateLimit-Reset: …
X-Run-Id: …              # on every response; correlates a call
Content-Type: application/problem+json   # on errors
Idempotency-Replayed: true               # on a replayed retry

How a client behaves safely

API behaviors
SituationWhat happens
RetriesSend an Idempotency-Key on any mutating call. A retry within 24 hours replays the stored response; a retry racing the original gets 409.
Another organization's record404, never 403, so its existence is not confirmed.
A list you may not read403 rather than an empty page, so "nothing here" and "not allowed" are never confused.
WebhooksEvery webhook is signed.
Errorsapplication/problem+json with a stable type per failure, catalogued with cause and remedy.
ProvisioningSCIM for joiners and leavers; OAuth2.
AgentsThe same capabilities as MCP tools under the same keys and permissions. /llms.txt for discovery.

Deliberately not in the API

Some actions have no route at all, so no permission could ever grant them.

  • Approving outreach: a named person must read a message before it reaches someone.
  • Writing screening answers: a model must not file its own account of a conversation.
  • Answering a candidate's review request: that is a human act with legal weight.
  • Declaring hiring jurisdictions: done on a screen that explains the consequences.

Not yet published

Latency, throughput and cost-per-call measurements, SLOs and a public status page do not exist yet as commitments. We'll publish them once they are measured.

Deploy anywhere

AWS Shipped
First-party Terraform, validated but not yet run against a live production account.
Managed Kubernetes Shipped
A Helm chart for managed Kubernetes, rehearsed on local Kubernetes. No specific managed service is listed as tested yet.
On-premise, single tenant Shipped
A chart that refuses a second tenant, rehearsed end to end on local Kubernetes. It has not yet been installed outside our own test environment.
Model endpoints Shipped
Anthropic, Amazon Bedrock or any OpenAI-compatible endpoint, switched by configuration. A non-western model adapter is a Stand-in.

About VoilaHire

VoilaHire was founded in November 2023 by Bala Thiruppanambakkam, who designed and built the platform.

Bala Thiruppanambakkam

Founder

Bala is an engineering executive with more than 25 years in payments, fintech and banking, where systems must keep a traceable record of every transaction. He architected and built VoilaHire.

  1. 2023 – presentFounder, VoilaHire
  2. 2019 – 2023Engineering Group Manager and Head of Braintree Vault, PayPal
  3. EarlierSenior Engineering Manager, Capital One
  4. EarlierEngineering, Visa

What we believe

  • A model should read and cite. It should not decide who gets a job.
  • A score without its evidence is a liability.
  • Say what works today, and say plainly what doesn't yet.

What's shipped, stated plainly

Exactly what works today, what you connect per deployment, and what remains. Last updated 5 October 2026.

Product status as of October 2026
StatusCapabilities
ShippedHiring pipeline and human-decision controls, recruiting agent, credential catalogue, compliance tooling, API and MCP, bias controls, self-identification store and adverse-impact measurement, structured interview kits and scorecards, background-check adjudication workflow, job distribution with a public feed, analytics views, offers, installable mobile app, data export, tamper-evident record, restore-proven backups, translated interface, advisory agent, single-tenant on-premise chart.
Connected per deploymentThird-party identity and liveness verification, enterprise workflow hooks, mailbox provider connectors (IMAP, Microsoft Graph, Gmail), live credential-registry checks, partner job boards, background-check providers, interview transcription, live calendar providers, card payments. Each does nothing until its provider is connected; job boards and background checks include a labeled simulated provider.
Stand-inMulti-region routing within one deployment (today, one deployment per region); the non-western extraction-model adapter (a real endpoint is a configuration change).
RemainingA run of the cloud Terraform and Helm against a live production account; a first on-premise install outside our test environment; production-accuracy evaluation of any self-hosted model before rollout.

The credential catalogue is a cited baseline, not exhaustive, and is guidance to verify locally rather than legal advice.

Accessibility statement

We want everyone to be able to use this website, including people who use assistive technology.

Privacy notice for this website

Terms of use for this website

That page doesn't exist

The address may be mistyped, or the page may have moved. Go to the home page or the product overview.