Ashby
Ashby is an all-in-one recruiting platform combining applicant tracking, CRM/sourcing, scheduling, and analytics, with embedded AI features including resume-to-criteria evaluation, AI-assisted application review, sourcing outreach, and scheduling agents.
HireAIScore rates Ashby 56 out of 100 (grade F, Substantial gaps) under rubric v1.0, last reviewed June 7, 2026. Ashby ranks 9 of 47 vendors rated in ATS-integrated AI, against a category average of 49. That score is drawn from 22 evidence items across 7 rubric criteria for Ashby — 16 with a cited source, 6 recording that nothing was located.
§ 01 - Company facts
- Legal name
- Ashby, Inc.
- Founded
- 2018
- Headquarters
- United States · US
- Pricing tier
- Mid
- Market side
- Employer-side (AEDT)
- Categories
- ATS-integratedSourcingSchedulingScreening
- Website
- ashbyhq.com
These are company details, not findings. They are editable by a verified representative and carry no weight in the score, which is built only from the cited evidence below.
§ 02 - Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%63
+12.6 · category avg 53
- 02
Bias Audit Transparency
Weight 18%62
+11.2 · category avg 45
- 03
FRIA Support
Weight 15%42
+6.3 · category avg 33
- 04
Data Governance Disclosure
Weight 15%58
+8.7 · category avg 56
- 05
Human Oversight Design
Weight 12%62
+7.4 · category avg 57
- 06
Post-Market Monitoring
Weight 12%42
+5.0 · category avg 42
- 07
Customer Documentation
Weight 8%63
+5.0 · category avg 59
Category avg is the mean raw score on that criterion across the 47 ATS-integrated AI vendors in scope of this rubric, this one included.
§ 03 - Strongest · weakest
Strongest category
Customer Documentation
Raw score 63 · contributes 5.0 to total.
63 against a 59 category average
Weakest category
Post-Market Monitoring
Raw score 42 · contributes 5.0 to total.
42 against a 42 category average
§ 04 - Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
Evidence ledger
- Items
- 22
- Documentation
- 12
- Audit report
- 1
- Public statement
- 3
- Absence
- 6
- With a source URL
- 16 of 22
- Source hostnames
- 3
- Fewest items
- 2
- Human Oversight Design
These figures measure how thoroughly Ashby was reviewed, not how Ashby performed — an absence row, recording that nothing was located, is counted like any other item.
Article 11 Technical Documentation
3 items63
- DocumentationCaptured Jun 7, 2026
Ashby's AI page sets out five responsible-AI pillars and states that 'any AI-generated recommendation must be explainable, either by exposing the reasoning behind it or enabling user review and override.'
- DocumentationCaptured Jun 7, 2026
The Trust Center lists AI-governance artifacts including a 'Responsible AI Statement' and 'AI Data Flow Diagrams' alongside the AI Bias Audit Report.
- AbsenceCaptured Jun 7, 2026
No ISO/IEC 42001 certification and no formal model card, system card, or instructions-for-use technical documentation pack were found on the AI page, docs, or Trust Center.
Bias Audit Transparency
3 items62
- Audit reportCaptured Jun 7, 2026
Publicly downloadable FairNow bias audit of Ashby's Criteria Evaluation model, prepared 23 August 2024, covering 123,610 applicant-criteria across the US and Europe with univariate and intersectional impact ratios and a finding of no disparate impact under NYC LL144.
https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf
- Public statementCaptured Jun 7, 2026
Ashby states it partners with independent auditor FairNow for third-party bias auditing and conducts regular fairness audits of its AI.
- AbsenceCaptured Jun 7, 2026
Only the August 2024 audit is published; no subsequent 2025 or 2026 annual bias audit was found on the downloadables path or Trust Center, so continuous/multi-year public auditing is not yet demonstrated.
FRIA Support
3 items42
- DocumentationCaptured Jun 7, 2026
Ashby's Terms for AI Features place deployer obligations on the customer, stating the 'Customer is solely responsible for all AI Input' and 'for its use of the AI Output,' including required disclosures and consents.
- DocumentationCaptured Jun 7, 2026
Product docs describe a configurable automated-processing legal notice that informs candidates their data may be processed by AI and lets them opt out, with skipped evaluation recorded for opted-out candidates.
- AbsenceCaptured Jun 7, 2026
No EU AI Act Article 27 Fundamental Rights Impact Assessment template or explicit FRIA deployer guidance was found on the AI page, AI-features terms, docs, or Trust Center.
Data Governance Disclosure
4 items58
- DocumentationCaptured Jun 7, 2026
Trust Center publishes SOC 1 and SOC 2 Type 2 reports (2024/2025/2026), EU-US/Swiss-US/UK Data Privacy Framework certifications, a Data Processing Agreement, a subprocessors list, and AI Data Flow Diagrams.
- Public statementCaptured Jun 7, 2026
Ashby states it does not train AI models on customer data, follows data minimization, and redacts PII from all resumes sent to AI models.
- DocumentationCaptured Jun 7, 2026
Security page details AES-256 encryption at rest and TLS 1.2/1.3 in transit on AWS, with annual SOC 2 Type 2 auditing.
- AbsenceCaptured Jun 7, 2026
No ISO/IEC 27001 or ISO/IEC 42001 certification is listed on the security page or Trust Center.
Human Oversight Design
2 items62
- DocumentationCaptured Jun 7, 2026
Ashby states the AI 'never ranks or gives numerical ratings to applicants, a human must always be involved' and provides citations for all AI outputs so users can verify, flag, and override analyses.
- DocumentationCaptured Jun 7, 2026
Docs describe per-criterion 'meets / does not meet / uncertain' evaluations, the ability to flag AI evaluations as incorrect or misleading, EEO violation warnings on criteria, and a candidate opt-out that skips evaluation.
Post-Market Monitoring
3 items42
- DocumentationCaptured Jun 7, 2026
Ashby publishes a responsible vulnerability disclosure program committing to acknowledge reports within five business days and resolve critical issues within a week, with reports to security@ashbyhq.com.
- Public statementCaptured Jun 7, 2026
The Safety pillar describes real-time monitoring, direct user feedback tools, and periodic reviews of flagged AI outputs.
- AbsenceCaptured Jun 7, 2026
No public continuous-monitoring dashboard or dedicated AI model-update changelog was found; monitoring relies on the general status page (status.ashbyhq.com) and the disclosure/security inbox.
Customer Documentation
4 items63
- DocumentationCaptured Jun 7, 2026
Detailed public AI product page covering each AI feature, the responsible-AI pillars, data handling, and compliance references.
- DocumentationCaptured Jun 7, 2026
Public knowledge-base article explaining how AI-assisted application review works, candidate notice/opt-out configuration, and EEO criteria warnings.
- DocumentationCaptured Jun 7, 2026
Trust Center provides a Data Processing Agreement, Terms for AI Features, subprocessors list, and downloadable compliance reports for customer due diligence.
- AbsenceCaptured Jun 7, 2026
No dedicated step-by-step EU AI Act deployer or NYC LL144 employer compliance guide was found beyond the published bias-audit PDF and AI-features terms.
§ 05 - Editorial notes
Company overview
Ashby (Ashby, Inc.) is a San Francisco-based, venture-backed recruiting software company founded in 2018 by Benjamin Encz and Abhik Pramanik. Its all-in-one platform spans applicant tracking, sourcing/CRM, interview scheduling, and analytics, and it has progressively layered AI on top - AI-assisted application review, a 'Criteria Evaluation' model that scores resumes against user-defined job criteria, sourcing/outreach personalization, an AI Notetaker, and scheduling agents. It serves mid-market and scaling tech companies (customers include Notion, Duolingo, Airtable, and Opendoor), placing it in the mid price tier.
Regulatory exposure
Ashby's AI-assisted application review and Criteria Evaluation features place it squarely within scope of NYC Local Law 144 (it is an AEDT-style screening tool) and likely Annex III high-risk territory under the EU AI Act once employment-AI obligations apply. The company explicitly acknowledges NYC LL 144, the EU AI Act, and (in its risk-assessment scope) Colorado, and provides candidate notice/opt-out tooling and in-product EEO bias warnings. Its disparate-impact exposure is directly tested in a public FairNow bias audit that found no group below the four-fifths threshold, but that audit is a single 2024 cycle and no later annual audit is publicly posted.
Path to a higher score
The single biggest lever is publishing a second consecutive annual NYC LL 144 bias audit (2025/2026) at a stable URL to demonstrate ongoing monitoring rather than a one-off. Beyond that: pursue ISO/IEC 42001 (or publish a formal model/system card and instructions-for-use pack) to strengthen Article 11 technical documentation; add explicit EU AI Act deployer guidance and an Article 27 FRIA template/checklist for customers; and stand up a public, continuously updated AI model-update changelog or monitoring surface rather than relying on the general status page and disclosure inbox.
§ Regulatory frame
What applies to ats-integrated ai.
Ranking features are inside EU AI Act Annex III §4 (high-risk) and inside NYC Local Law 144 when they affect NYC-based candidates. Customers should treat the AI surface as a distinct deployer-FRIA scope from the rest of the ATS.
§ Compare
Build any comparison→Ashby against its nearest-scoring peers.
In ATS-integrated AI.
§ Others rated in ATS-integrated AI
All ats-integrated vendors→Ranked 9 of 47 by weighted total under rubric v1.0. The ordering is arithmetic on the rubric and carries no view on which tool suits a given hiring process.
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework - the consulting firm that operates this directory - provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.