Draup
Draup is an AI-powered talent- and sales-intelligence platform that aggregates over a billion public professional profiles into skills, roles and labour-market analytics, and surfaces ranked candidate shortlists for enterprise workforce planning and recruiting.
HireAIScore rates Draup 42 out of 100 (grade F, Substantial gaps) under rubric v1.0, last reviewed August 2, 2026. Draup ranks 34 of 49 vendors rated in Candidate sourcing AI, against a category average of 48. That score is drawn from 30 evidence items across 7 rubric criteria for Draup — 23 with a cited source, 7 recording that nothing was located.
§ 01 - Company facts
- Legal name
- Draup, Inc.
- Founded
- 2017
- Headquarters
- United States · US
- Pricing tier
- Enterprise
- Market side
- Employer-side (AEDT)
- Categories
- SourcingScreening
- Website
- draup.com
These are company details, not findings. They are editable by a verified representative and carry no weight in the score, which is built only from the cited evidence below.
§ 02 - Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%48
+9.6 · category avg 51
- 02
Bias Audit Transparency
Weight 18%33
+5.9 · category avg 47
- 03
FRIA Support
Weight 15%25
+3.8 · category avg 32
- 04
Data Governance Disclosure
Weight 15%54
+8.1 · category avg 54
- 05
Human Oversight Design
Weight 12%58
+7.0 · category avg 56
- 06
Post-Market Monitoring
Weight 12%28
+3.4 · category avg 41
- 07
Customer Documentation
Weight 8%57
+4.6 · category avg 57
Category avg is the mean raw score on that criterion across the 49 Candidate sourcing AI vendors in scope of this rubric, this one included.
§ 03 - Strongest · weakest
Strongest category
Human Oversight Design
Raw score 58 · contributes 7.0 to total.
58 against a 56 category average
Weakest category
FRIA Support
Raw score 25 · contributes 3.8 to total.
25 against a 32 category average
§ 04 - Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
Evidence ledger
- Items
- 30
- Documentation
- 20
- Public statement
- 3
- Absence
- 7
- With a source URL
- 23 of 30
- Source hostnames
- 2
- Fewest items
- 2
- FRIA Support
These figures measure how thoroughly Draup was reviewed, not how Draup performed — an absence row, recording that nothing was located, is counted like any other item.
Article 11 Technical Documentation
4 items48
- DocumentationCaptured Aug 2, 2026
The talent-acquisition page asserts that "Outputs comply with NIST AI RMF, ISO/IEC 42001, and EU AI Act standards, ensuring transparency in each hiring decision" and describes "Explainable & Ethical AI", but supplies no model card, conformity assessment or certificate to support the claim.
- DocumentationCaptured Aug 2, 2026
A site-wide "Data Trust & Methodology at Draup" block sets out six areas including "AI Governance and Bias Mitigation", stating that "Our governance framework combines automated evaluations with Human-in-the-Loop reviews."
- DocumentationCaptured Aug 2, 2026
The data/API page documents scale and integration surface (1B+ profiles, 27K+ skills, REST API, MCP, data dictionary) but contains no model documentation, evaluation results or explainability specification.
- AbsenceCaptured Aug 2, 2026
No ISO 42001 certificate, system or model card, instructions-for-use or Annex IV-style technical documentation was found: draup.com/security returns HTTP 404, no trust centre exists, and none of the 39 titles in the whitepaper library address AI governance, explainability or model documentation.
Bias Audit Transparency
5 items33
- Public statementCaptured Aug 2, 2026
Draup claims "Explainable & Ethical AI - Every profile is bias-checked, lineage-traceable, and human-in-the-loop validated" without naming an auditor, methodology, sample or date.
- Public statementCaptured Aug 2, 2026
The methodology block states Draup uses "statistical checks, audits, and cross-source comparisons to reduce demographic and structural bias", describing internal self-assessment rather than independent audit.
- Public statementCaptured Aug 2, 2026
The GDPR page displays SOC 2, GDPR, ISO 27001 and EAIGG badges, with EAIGG membership presented alongside a claim to audit for bias.
- DocumentationCaptured Aug 2, 2026
EAIGG describes itself as "a 501c3 non-profit organization committed to building a global community of AI practitioners, entrepreneurs, and technology investors"- a community body, not an audit or certification authority - and does not list Draup as a member.
- AbsenceCaptured Aug 2, 2026
No NYC LL 144 bias audit, and no independent audit by BABL AI, DCI, ORCAA, Warden AI, Holistic AI, Credo AI or ConductorAI, nor any academic audit, was found on draup.com, in its whitepaper library, on its press page, or through web search.
FRIA Support
2 items25
- AbsenceCaptured Aug 2, 2026
No Article 27 Fundamental Rights Impact Assessment template, deployer-obligation guidance, EU AI Act risk classification or customer compliance pack was found anywhere on draup.com; a site-restricted search for "AI Act" returned no results and draup.com/security returns HTTP 404.
- DocumentationCaptured Aug 2, 2026
The terms warn that AI features "may produce outputs that are inaccurate, incomplete, biased, or otherwise unsuitable for a particular purpose" but impose no deployer compliance obligations and give no EEO or employment-decision guidance.
Data Governance Disclosure
6 items54
- DocumentationCaptured Aug 2, 2026
The privacy policy discloses that data is gathered from "your public profiles (such as professional social network sites and social media sites where you have publicly posted information), other public websites and web platforms, from data brokers or other data vendors" and enumerates categories including professional history, inferences and professional network pictures.
- DocumentationCaptured Aug 2, 2026
The API page describes "token-based scopes, PII masking, and audit trails" for API and MCP access, plus a downloadable data dictionary specifying field definitions and formats.
- DocumentationCaptured Aug 2, 2026
The methodology block states that "All aggregate insights related to buyers, roles, skills, and locations are grounded in structured, anonymized human and organizational profiles" and describes data-hygiene deduplication and compensation guardrails.
- DocumentationCaptured Aug 2, 2026
Draup offers self-service profile deletion, stating "By deleting your individual profile, you are also opting out of the sale of the information contained in it."
- DocumentationCaptured Aug 2, 2026
The GDPR page confirms "we have appointed a Data Protection Officer" and describes access and erasure rights for EU data subjects.
- AbsenceCaptured Aug 2, 2026
No ISO 42001, no training-data exclusion list, no sub-processor register and no accessible SOC 2 or ISO 27001 certificate were found; the SOC 2 and ISO 27001 claims appear only as badges, and draup.com/security returns HTTP 404.
Human Oversight Design
5 items58
- DocumentationCaptured Aug 2, 2026
The product surfaces "Ranked profiles with the why - task and skill evidence, level alignment, and location fit" and offers "dedicated Diversity filters (Ethnicity, Gender, Veterans) and a Blind Hiring mode to reduce unconscious bias."
- DocumentationCaptured Aug 2, 2026
Curie is framed as a decision-support assistant that generates recommendations and forecasts rather than making autonomous hiring decisions, with human-in-the-loop review cited in its governance framework.
- DocumentationCaptured Aug 2, 2026
Etter is described as providing "transparency with rationale and collaborative workflows", giving documented justification for each role-redesign recommendation.
- DocumentationCaptured Aug 2, 2026
The site-wide methodology block states that Draup's governance framework "combines automated evaluations with Human-in-the-Loop reviews" applied before insights reach the platform.
- AbsenceCaptured Aug 2, 2026
No documented recruiter override controls, per-jurisdiction compliance toggles, candidate-notification features or customer-facing audit-log functionality were found; the human-in-the-loop described governs Draup's internal data pipeline rather than the customer's hiring decision workflow.
Post-Market Monitoring
3 items28
- AbsenceCaptured Aug 2, 2026
No public incident channel, uptime or status page (status.draup.com does not resolve in DNS), model-update changelog, continuous monitoring dashboard, security.txt or vulnerability disclosure policy was found.
- DocumentationCaptured Aug 2, 2026
A Data Protection Officer contact reachable at info@draup.com is published as the only standing governance channel.
- DocumentationCaptured Aug 2, 2026
The privacy policy provides privacy@draup.com for opt-out and data-subject requests, but no security or model-incident reporting contact.
Customer Documentation
5 items57
- DocumentationCaptured Aug 2, 2026
A detailed public product page covers candidate sourcing, ranked shortlists, diversity filters, blind hiring and ATS export.
- DocumentationCaptured Aug 2, 2026
Public API and integration documentation lists REST/SDK access, cloud data feeds, MCP support, 30+ HRIS connectors and a downloadable data dictionary.
- DocumentationCaptured Aug 2, 2026
A dedicated GDPR page sets out compliance commitments, names a Data Protection Officer and describes access, erasure and opt-out rights.
- DocumentationCaptured Aug 2, 2026
Public terms of use include AI-specific clauses on acceptable use of AI features and disclaimers about output accuracy and bias.
- AbsenceCaptured Aug 2, 2026
No publicly available DPA, no NYC Local Law 144 guidance, no EU AI Act deployer documentation and no compliance or trust hub were found on draup.com.
§ 05 - Editorial notes
Company overview
Draup was founded in 2017 by Vijay Swaminathan and Vamsee Tirukkala, originally headquartered in Bangalore, India and now listing its primary office at The Woodlands, Texas, following a USD 20 million Series A from HKW announced in March 2022. The platform aggregates 1B+ professional profiles, 27K+ skills, 3,500+ roles and 6,100+ locations drawn from public datasets, professional networks, data brokers and government labour sources, and applies 150+ machine-learning models plus two agentic assistants - Curie for workforce strategy and Etter for AI-driven work redesign - across workforce planning, predictive skills architecture, university hiring, peer benchmarking and outbound candidate sourcing. Draup reports serving 300+ global enterprises including five of the Fortune 10, sells on a custom enterprise quote basis, and distributes data via REST API, SDKs, cloud data feeds, Model Context Protocol and 30+ HRIS/ATS connectors including Workday, SAP SuccessFactors and Greenhouse.
Regulatory exposure
Draup's talent-acquisition module produces "Ranked profiles" and exportable candidate shortlists that feed directly into customer ATSs, which places it plausibly within Annex III of the EU AI Act as a high-risk system used for recruitment and candidate filtering, and potentially within NYC Local Law 144 where those rankings substantially assist screening. The gap between Draup's claims and its published evidence is the central concern: the talent-acquisition page asserts that "Outputs comply with NIST AI RMF, ISO/IEC 42001, and EU AI Act standards, ensuring transparency in each hiring decision," yet Draup publishes no technical documentation, model card, conformity assessment, certificate or bias audit to substantiate any of it, and there is no ISO 42001 certification claim anywhere on the site. Its repeated line "As an EAIGG member, we audit for bias" refers to membership of the Ethical AI Governance Group, a 501(c)(3) practitioner community rather than an audit or certification body, and Draup does not appear on EAIGG's own site. There is no /security page (HTTP 404), no trust centre, no status page (status.draup.com does not resolve), and no NYC LL 144 or EU AI Act deployer guidance. Separately, the product exposes "Diversity filters (Ethnicity, Gender, Veterans)," a capability that deployers should scrutinise carefully under Title VII and EU non-discrimination law even when used for outbound sourcing rather than selection.
Path to a higher score
The fastest credibility win is to reconcile claim with evidence: either publish an ISO/IEC 42001 certificate and a NIST AI RMF mapping, or soften the "outputs comply with ... EU AI Act standards" assertion on the talent-acquisition page. Beyond that, Draup should commission and publicly post an independent bias audit of its candidate-ranking models in NYC LL 144 format - naming auditor, date, selection and scoring rates by sex and race/ethnicity, and intersectional categories - and repeat it annually; publish an Annex IV-style technical documentation pack or model card covering the ranking models, their training inputs, known limitations and accuracy metrics; add an Article 27 FRIA template plus explicit deployer-obligation guidance for EU customers; stand up a trust centre exposing the SOC 2 report and ISO 27001 certificate under NDA, a sub-processor register, a training-data exclusion list and a standard DPA; and add a public status page, a security.txt/vulnerability disclosure contact and a model-update changelog so post-market monitoring is externally visible.
§ Regulatory frame
What applies to candidate sourcing ai.
Ranking outputs are inside Annex III §4 when they influence hiring decisions. GDPR Article 22 (automated decision-making) and the GDPR rights around profiling apply independently for EU candidates.
§ Compare
Build any comparison→Draup against its nearest-scoring peers.
In Candidate sourcing AI.
§ Others rated in Candidate sourcing AI
All sourcing vendors→Ranked 34 of 49 by weighted total under rubric v1.0. The ordering is arithmetic on the rubric and carries no view on which tool suits a given hiring process.
- 31Fountain44F
- 32JazzHR44F
- 33Breezy HR43F
- 34DraupThis profile42F
- 35Recruitee42F
- 36hireEZ42F
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework - the consulting firm that operates this directory - provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.