Gloat
Gloat is an AI-powered internal talent marketplace and "agentic HR" platform that matches an employer's existing employees to internal job openings, gigs, projects, mentorships, and learning based on inferred skills and career goals.
HireAIScore rates Gloat 47 out of 100 (grade F, Substantial gaps) under rubric v1.0, last reviewed August 2, 2026. Gloat ranks 28 of 49 vendors rated in Candidate sourcing AI, against a category average of 48. That score is drawn from 29 evidence items across 7 rubric criteria for Gloat — 21 with a cited source, 8 recording that nothing was located.
§ 01 - Company facts
- Legal name
- Gloat Ltd.
- Founded
- 2015
- Headquarters
- United States · US
- Pricing tier
- Enterprise
- Market side
- Employer-side (AEDT)
- Categories
- SourcingAssessment
- Website
- gloat.com
These are company details, not findings. They are editable by a verified representative and carry no weight in the score, which is built only from the cited evidence below.
§ 02 - Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%48
+9.6 · category avg 51
- 02
Bias Audit Transparency
Weight 18%38
+6.8 · category avg 47
- 03
FRIA Support
Weight 15%28
+4.2 · category avg 32
- 04
Data Governance Disclosure
Weight 15%58
+8.7 · category avg 54
- 05
Human Oversight Design
Weight 12%62
+7.4 · category avg 56
- 06
Post-Market Monitoring
Weight 12%42
+5.0 · category avg 41
- 07
Customer Documentation
Weight 8%62
+5.0 · category avg 57
Category avg is the mean raw score on that criterion across the 49 Candidate sourcing AI vendors in scope of this rubric, this one included.
§ 03 - Strongest · weakest
Strongest category
Customer Documentation
Raw score 62 · contributes 5.0 to total.
62 against a 57 category average
Weakest category
FRIA Support
Raw score 28 · contributes 4.2 to total.
28 against a 32 category average
§ 04 - Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
Evidence ledger
- Items
- 29
- Documentation
- 18
- Audit report
- 1
- Public statement
- 2
- Absence
- 8
- With a source URL
- 21 of 29
- Source hostnames
- 4
- Fewest items
- 3
- FRIA Support
These figures measure how thoroughly Gloat was reviewed, not how Gloat performed — an absence row, recording that nothing was located, is counted like any other item.
Article 11 Technical Documentation
4 items48
- DocumentationCaptured Aug 2, 2026
A dedicated ethical AI page sets out five principles (enhancing rather than replacing human decision-making, fairness as a north star, proactive monitoring and auditing, ongoing transparency, accountability) and states that users can learn why particular candidates and opportunities were suggested, removing the "black box" around AI suggestions.
- DocumentationCaptured Aug 2, 2026
The AI technology page describes the system architecture (knowledge graph, 14 intelligent tools, personalization engine, proprietary embedding models) and asserts that "What was considered. What was excluded. Why. Every decision is transparent and auditable," but links no model card, whitepaper or methodology document.
- DocumentationCaptured Aug 2, 2026
A Governance Engine page documents six enforced rule categories (approval workflows, access and permissions/RBAC, eligibility criteria, org hierarchy, compensation bands, compliance policies) and states that agents "can tell users why - and what alternatives exist."
- AbsenceCaptured Aug 2, 2026
No model card, system card, technical documentation pack, ISO/IEC 42001 certification or EU AI Act reference was found across gloat.com's page sitemap, the security-and-compliance page, the four ai-technology pages, the ethical AI page, or a site-restricted search for "ISO 42001" and "AI Act".
Bias Audit Transparency
4 items38
- Public statementCaptured Aug 2, 2026
Gloat claims "regular algorithmic auditing" comprising "continuous self-monitoring of models" and "third-party audits," and says customers "have the ability to test how models behave in their environment"- but names no auditor, gives no date, methodology or impact-ratio results, and links no report.
- AbsenceCaptured Aug 2, 2026
No NYC Local Law 144 bias audit summary or AEDT notice was found anywhere on gloat.com, despite LL 144 covering the screening of employees for promotion, which is Gloat's core use case; searches restricted to gloat.com for "bias audit" and "Local Law 144" returned nothing.
- AbsenceCaptured Aug 2, 2026
No named independent auditor (Warden AI, Holistic AI, BABL AI, DCI, ORCAA, Credo AI, ConductorAI) or academic audit of Gloat's matching models was found via web search or on the ethical AI, security-and-compliance, AI technology or governance-engine pages.
- DocumentationCaptured Aug 2, 2026
Gloat's bias-mitigation blog post offers general principles (multi-matching strategies, transparency, treating matches as recommendations rather than final decisions) without disclosing Gloat's own testing methodology, validation results or any third-party review.
FRIA Support
3 items28
- AbsenceCaptured Aug 2, 2026
No EU AI Act Article 27 Fundamental Rights Impact Assessment template, deployer-obligation guidance, or any mention of the EU AI Act was found on gloat.com - checked the page sitemap, security-and-compliance, ethical AI, all four ai-technology pages, the privacy and users-privacy notices, and the responsible-AI blog cluster.
- DocumentationCaptured Aug 2, 2026
A Compliance Center portal exists but is a login wall stating only approved users may access it and that new users require administrator approval; it references SOC 2 Type II and ISO 27001 and directs enquiries to a Gloat representative, so no deployer-facing assessment material is publicly obtainable.
- DocumentationCaptured Aug 2, 2026
The end-user privacy notice supplies material a deployer could reuse in an impact assessment - disclosure of AI-driven recommendations for jobs, career pathing, skills, learning and mentorship, plus a human-review escalation route - but it is framed as a privacy notice, not an AI Act deployer assessment.
Data Governance Disclosure
5 items58
- DocumentationCaptured Aug 2, 2026
Gloat publishes a concrete AI input exclusion list, stating its "AI does not digest any demographic data or proxies" and naming gender, race, ethnicity, ability, university name and native language among the excluded bias-prone inputs.
- Audit reportCaptured Aug 2, 2026
Gloat states it holds third-party-verified SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018 attestations plus self-assessed GDPR and CSA CAIQ/CCM, with AES-256 at rest, TLS 1.2+ in transit, MFA/SSO/JIT access, monthly vulnerability scans, annual third-party penetration testing and optional regional data residency.
- DocumentationCaptured Aug 2, 2026
A published Technical and Organisational Measures annex documents GDPR Article 32-style controls including encryption, segregation of duties, quarterly access-log reviews, and annual subprocessor risk assessments with review of third-party audit reports - though it contains no AI or automated-decision-making provisions.
https://resources.gloat.com/technical-organisational-measures/
- DocumentationCaptured Aug 2, 2026
The privacy policy states that personal information "is not used to develop, improve, or train Generative AI and/or ML models" in the website chatbot context, and documents EEA/UK transfer mechanisms (adequacy, SCCs, UK Addendum, US Data Privacy Framework).
- AbsenceCaptured Aug 2, 2026
No public subprocessor list, no training-data provenance or dataset documentation, and no published data retention schedule - the security page states the retention policy is available only after an NDA, and the compliance portal holding certifications is login-gated.
Human Oversight Design
4 items62
- DocumentationCaptured Aug 2, 2026
The end-user privacy notice states plainly that "Automated decisions without human involvement are not made on the Platform," that "AI will not automatically apply on behalf of an employee for an opportunity for which it recommended," that "AI insights and recommendations are assistive only," and that employees "may request clarification on AI-based suggestions or ask for human review" via their employer.
- DocumentationCaptured Aug 2, 2026
The Governance Engine enforces multi-level approval chains with delegation and escalation paths, inherits customer access controls so a manager sees only their team, applies eligibility criteria such as performance thresholds and readiness indicators, and has agents explain why an outcome occurred and what alternatives exist.
- DocumentationCaptured Aug 2, 2026
Gloat describes a "human-in-the-loop" model as its operating principle and commits to "enhancing - but not replacing - human awareness and decision making," with users able to learn why particular candidates and opportunities were suggested.
- AbsenceCaptured Aug 2, 2026
No documentation of customer-accessible audit logs of AI recommendations, no per-jurisdiction compliance toggles (e.g. an NYC AEDT or EU high-risk mode), and no published override-and-reason-capture workflow was found; the administrator help center at help.gloat.com redirects to SSO login and is not publicly readable.
Post-Market Monitoring
4 items42
- DocumentationCaptured Aug 2, 2026
Gloat operates a public system status page showing current operational state and a dated incident history, with subscription via email, SMS, Slack, Microsoft Teams webhook, RSS and Atom.
- DocumentationCaptured Aug 2, 2026
The security page discloses an ongoing monitoring cadence - monthly vulnerability scans, annual third-party penetration testing, a CISO-led programme, regularly tested business continuity and disaster recovery plans - and provides privacy@gloat.com for data-subject and support requests.
- Public statementCaptured Aug 2, 2026
Gloat asserts "proactive monitoring and auditing" including "continuous self-monitoring of models," but publishes no monitoring results, metrics or dashboard against which the claim can be checked.
- AbsenceCaptured Aug 2, 2026
No coordinated vulnerability disclosure programme, no security.txt (gloat.com/.well-known/security.txt returns HTTP 404), no dedicated security contact address, no public model-update changelog or release notes (help.gloat.com is behind SSO), and no fairness or drift monitoring dashboard.
Customer Documentation
5 items62
- DocumentationCaptured Aug 2, 2026
A detailed public product page explains matching to internal jobs, projects, mentorships and learning, and describes manager, recruiter and employee-facing surfaces including talent pools, skills gap identification and the Skills Landscape.
- DocumentationCaptured Aug 2, 2026
A public security and compliance page consolidates certifications, encryption, access control, data residency and business continuity information and points customers to a Compliance Center for audit reports.
- DocumentationCaptured Aug 2, 2026
Gloat publishes a separate end-user privacy notice aimed at customers' employees that discloses AI-based recommendations and the human-review route - documentation deployers can point their workforce to directly.
- DocumentationCaptured Aug 2, 2026
Part of a cluster of at least ten responsible-AI blog posts (ethical AI 101, ethical AI checklist, ethical AI mistakes, mitigating bias, representation for ethical AI), though the content is general thought leadership rather than Gloat-specific compliance disclosure.
- AbsenceCaptured Aug 2, 2026
No publicly available Data Processing Agreement, no NYC Local Law 144 customer guidance, no EU AI Act deployer guidance, and no public product/admin documentation - the help center at help.gloat.com redirects to SSO and gloat.com/guides/ returns HTTP 500.
§ 05 - Editorial notes
Company overview
Gloat was founded in 2015 (originally as Workey) by Ben Reuveni, Danny Shteinberg and Amichai Schreiber, is headquartered in New York with a major engineering presence in Tel Aviv, and operates through the entity named in its privacy policy as Gloat Ltd. It raised a $57M Series C led by Accel (2021) and a $90M Series D led by Generation Investment Management (2022), and sells to very large enterprises including Unilever, HSBC, Mastercard, PepsiCo, Nestlé, Schneider Electric and Standard Chartered. The core product deconstructs roles and projects into skills and matches them against an employee knowledge graph; in March 2026 Gloat launched "Gloat Agentic HR", layering workforce agents and a rules-extraction Governance Engine on that graph, with integrations into Workday, SuccessFactors, Oracle HCM, Microsoft Teams, Slack and Copilot. Pricing is unpublished and the deployment profile is unambiguously enterprise.
Regulatory exposure
Gloat's exposure is unusual in that it sits on the internal-mobility and promotion side of employment - which the same statutes cover explicitly. EU AI Act Annex III(4) captures AI used for promotion, task allocation and evaluation in work relationships, so Gloat's matching, skills inference and project allocation likely make it a provider of a high-risk system with Article 11 documentation, Article 10 data governance, Article 14 oversight and Article 72 post-market monitoring duties, and give EU customers Article 27 FRIA duties. NYC Local Law 144 defines an employment decision to include screening employees for promotion, so US customers surfacing internal candidates in New York City may need an annual independent bias audit - and Gloat publishes none. Illinois HB 3773 (in force January 2026) expressly reaches AI used in promotion and selection for training, and Colorado SB 24-205 treats promotion as a consequential decision with developer disclosure duties. The strongest mitigation is genuine: Gloat's end-user notice states that "Automated decisions without human involvement are not made on the Platform," which materially limits Article 22 and AEDT-style risk. The gap is evidentiary rather than conceptual - Gloat asserts fairness practices without publishing anything a regulator or deployer could inspect.
Path to a higher score
The highest-value move is publishing an actual algorithmic fairness audit: Gloat already claims "third-party audits" and "continuous self-monitoring of models" but names no auditor, date, methodology or result, so commissioning a named independent audit (Warden AI, Holistic AI, BABL AI, DCI or ORCAA) covering promotion and internal-mobility matching and posting a downloadable summary would move bias audit transparency from the high 30s toward 70+. Second, an Annex III-oriented technical pack - a system card with intended purpose, model description, known limitations, accuracy metrics and instructions-for-use, plus ISO/IEC 42001 alongside the existing ISO 27001 family. Third, EU AI Act deployer material: an Article 27 FRIA template and a provider-versus-deployer obligation split would lift the weakest score on the board. Finally, ungating - the compliance portal sits behind login approval and the help center behind SSO, so a public trust page exposing certifications, a subprocessor list, a DPA and a model-update changelog would convert existing internal maturity into scoreable public evidence at low cost.
§ Regulatory frame
What applies to candidate sourcing ai.
Ranking outputs are inside Annex III §4 when they influence hiring decisions. GDPR Article 22 (automated decision-making) and the GDPR rights around profiling apply independently for EU candidates.
§ Compare
Build any comparison→Gloat against its nearest-scoring peers.
In Candidate sourcing AI.
§ Others rated in Candidate sourcing AI
All sourcing vendors→Ranked 28 of 49 by weighted total under rubric v1.0. The ordering is arithmetic on the rubric and carries no view on which tool suits a given hiring process.
- 25Workable48F
- 26Covey47F
- 27Teamtailor47F
- 28GloatThis profile47F
- 29Jobvite45F
- 30Dover45F
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework - the consulting firm that operates this directory - provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.