HomeVendorsJobylon

Jobylon

Jobylon is a Stockholm-based applicant tracking system and talent CRM for enterprise employers whose optional AI features score each applicant's CV against the job description, suggest existing candidates for other open roles, draft job ads and screening questions, and run candidate screening and interview scheduling over WhatsApp, SMS and email.

HireAIScore rates Jobylon 48 out of 100 (grade F, Substantial gaps) under rubric v1.0, last reviewed September 25, 2026. Jobylon ranks 33 of 77 vendors rated in ATS-integrated AI, against a category average of 47. That score is drawn from 33 evidence items across 7 rubric criteria for Jobylon — 28 with a cited source, 5 recording that nothing was located.

§ 01 - Company facts

Legal name
Jobylon AB
Founded
2011
Headquarters
Sweden · SE
Pricing tier
Mid
Market side
Employer-side (AEDT)
Categories
ATS-integratedScreeningSourcingScheduling
Website
jobylon.com

These are company details, not findings. They are editable by a verified representative and carry no weight in the score, which is built only from the cited evidence below.

§ 02 - Score breakdown

§ Score breakdown

Category scoring

Weighted contribution shown to the right of each bar.

  1. 01

    Article 11 Technical Documentation

    Weight 20%

    55

    +11.0 · category avg 51

  2. 02

    Bias Audit Transparency

    Weight 18%

    28

    +5.0 · category avg 41

  3. 03

    FRIA Support

    Weight 15%

    36

    +5.4 · category avg 32

  4. 04

    Data Governance Disclosure

    Weight 15%

    58

    +8.7 · category avg 54

  5. 05

    Human Oversight Design

    Weight 12%

    60

    +7.2 · category avg 57

  6. 06

    Post-Market Monitoring

    Weight 12%

    45

    +5.4 · category avg 42

  7. 07

    Customer Documentation

    Weight 8%

    60

    +4.8 · category avg 59

Category avg is the mean raw score on that criterion across the 77 ATS-integrated AI vendors in scope of this rubric, this one included.

Total weighted score: 47.5(rounded to 48 for display)

§ 03 - Strongest · weakest

Strongest category

Customer Documentation

Raw score 60 · contributes 4.8 to total.

60 against a 59 category average

Weakest category

Bias Audit Transparency

Raw score 28 · contributes 5.0 to total.

28 against a 41 category average

§ 04 - Cited evidence

Download diligence record→

§ Evidence

Cited per category

Every score is backed by at least one cited piece of evidence.

Evidence ledger

Items
33
Documentation
24
Audit report
1
Public statement
3
Absence
5
With a source URL
28 of 33
Source hostnames
4
Fewest items
4
Article 11 Technical Documentation

These figures measure how thoroughly Jobylon was reviewed, not how Jobylon performed — an absence row, recording that nothing was located, is counted like any other item.

Article 11 Technical Documentation

4 items55
  • DocumentationCaptured Sep 25, 2026

    A help-centre article dated 25 August 2026 describes the AI Matcher. It uses a pre-trained open-source embedding model that is static, is not retrained on customer data and was fine-tuned on synthetic and curated job-ad and candidate data. It compares CV and job-description text to produce a 0-100 similarity score. System architecture, data-flow and AI Act risk assessment documents are offered only on request.

    https://support.jobylon.com/en/articles/802972-jobylon-ai-matcher-how-it-works

  • DocumentationCaptured Sep 25, 2026

    The Vanta trust center lists Jobylon AI Matching, Jobylon Copilot and a Copilot Evaluation Report under AI and Responsible Use, all behind Request access; none is publicly downloadable.

    https://trust.jobylon.com

  • Public statementCaptured Sep 25, 2026

    The AI recruiting page sets out responsible-AI principles: vendor selection, no model training on customer data, legal compliance, editable outputs and a risk analysis before each feature. Its FAQ says Jobylon has started evaluating its features against Annex III but gives no classification.

    https://www.jobylon.com/solutions/ai-recruiting

  • AbsenceCaptured Sep 25, 2026

    No public model card naming the embedding model or LLM version, no accuracy or validation metrics, no instructions for use and no ISO/IEC 42001 certification were found on jobylon.com (sitemap reviewed), support.jobylon.com or trust.jobylon.com. /ai-policy, /responsible-ai and /ai-transparency on jobylon.com return 404.

    Have a URL that disputes this?→

Bias Audit Transparency

4 items28
  • AbsenceCaptured Sep 25, 2026

    No NYC LL 144 bias-audit summary, independent fairness audit or adverse-impact statistics for the AI Matcher, talent suggestions or AI Hiring Assistant were found on jobylon.com (sitemap reviewed), in all nine support.jobylon.com collections or on trust.jobylon.com. trust.warden-ai.com/jobylon returns 404.

    Have a URL that disputes this?→

  • Public statementCaptured Sep 25, 2026

    The bias FAQ answers by pointing to Anthropic's own model evaluations and to user control over prompts. That does not cover the separate open-source embedding model that produces the match scores.

    https://www.jobylon.com/solutions/ai-recruiting

  • DocumentationCaptured Sep 25, 2026

    Mitigation is design-level only: the matcher does not take age, gender or ethnicity as inputs, but no testing for proxy effects in CV text is reported.

    https://support.jobylon.com/en/articles/802972-jobylon-ai-matcher-how-it-works

  • DocumentationCaptured Sep 25, 2026

    A configurable anonymous-recruitment feature can hide fields such as name and email until a chosen pipeline stage; this is a process control, not an audit.

    https://support.jobylon.com/en/articles/105666-anonymous-recruitment

FRIA Support

4 items36
  • DocumentationCaptured Sep 25, 2026

    A February 2024 explainer lists generic deployer duties for HR and TA teams: use the system as the provider instructs, keep human oversight, meet transparency duties, monitor operation, and manage risks and report incidents. It never mentions Art. 27 or fundamental rights impact assessments and does not apply these duties to Jobylon's features.

    https://www.jobylon.com/blog/eu-ai-act-what-hr-teams-need-to-know

  • DocumentationCaptured Sep 25, 2026

    A request-only trust package offers a DPA with three annexes, an SLA, terms of service and 13 sub-processor Transfer Risk & Impact Assessments. The TRIAs are GDPR transfer assessments, not FRIAs.

    https://trust.jobylon.com

  • DocumentationCaptured Sep 25, 2026

    A form-gated AI Buyer's Guide written with Hubert and updated 21 November 2025 gives buyers questions to ask vendors about EU AI Act compliance. It is procurement guidance, not a FRIA template.

    https://www.jobylon.com/guides-reports/ai-buyers-guide-for-recruitment-software

  • AbsenceCaptured Sep 25, 2026

    No FRIA template, Art. 26/27 deployer checklist or instructions for use were found on jobylon.com, support.jobylon.com or trust.jobylon.com. The AI Act risk assessment mentioned in the matcher article is available only on request.

    Have a URL that disputes this?→

Data Governance Disclosure

5 items58
  • DocumentationCaptured Sep 25, 2026

    The matcher reads only CV and job-description text and excludes demographic attributes (age, gender, ethnicity). It is not trained on customer applicant data and was fine-tuned on synthetic and manually curated data.

    https://support.jobylon.com/en/articles/802972-jobylon-ai-matcher-how-it-works

  • Public statementCaptured Sep 25, 2026

    Jobylon states that its LLM neither stores nor trains on customer inputs or outputs, and that no data is retained for model training.

    https://www.jobylon.com/solutions/ai-recruiting

  • Audit reportCaptured Sep 25, 2026

    A publicly viewable ISO/IEC 27001:2022 certificate for Jobylon AB was issued by Prescient Security LLC (IAS-accredited), certificate no. 122514. First issued 10 June 2024 and valid until 9 June 2027, it covers the platform for job ads and candidate-data management hosted on AWS and Heroku. The Statement of Applicability is gated.

    https://trust.jobylon.com

  • DocumentationCaptured Sep 25, 2026

    The security policy page, last revised September 2022, documents EU-only AWS data residency, AES-256 encryption at rest, TLS 1.2+ in transit, annual third-party penetration tests and platform audit and activity logs.

    https://www.jobylon.com/security-measures

  • DocumentationCaptured Sep 25, 2026

    The public sub-processor list gives server locations (mostly EU; optional Twilio SMS in the US) and 30 days' advance notice of changes. It names no AI model or LLM provider, although Jobylon says it uses Anthropic models.

    https://www.jobylon.com/subprocessors

Human Oversight Design

5 items60

Post-Market Monitoring

5 items45
  • DocumentationCaptured Sep 25, 2026

    A public Atlassian Statuspage covers seven components (API, App, Feed, Webhooks, Website, Analytics, Custom Dashboards) with email, Slack and RSS/Atom subscriptions. No component covers the AI features.

    https://status.jobylon.com

  • DocumentationCaptured Sep 25, 2026

    The incident feed lists 24 incidents from April 2019 to 17 July 2026. Several state root causes, such as the July 2026 outage caused by an email-notification component overloading servers, and two 2020 postmortems name preventive actions.

    https://status.jobylon.com/api/v2/incidents.json

  • DocumentationCaptured Sep 25, 2026

    The responsible disclosure policy directs reports to security@jobylon.com, promises acknowledgement within five business days and aims to resolve critical issues within one week.

    https://www.jobylon.com/responsible-disclosure-policy

  • DocumentationCaptured Sep 25, 2026

    The security policy describes an incident routine that escalates to the CTO and Legal, a personal-data-breach routine, and APM and log monitoring with alerting.

    https://www.jobylon.com/security-measures

  • AbsenceCaptured Sep 25, 2026

    No AI-specific post-market monitoring was found on jobylon.com, support.jobylon.com, status.jobylon.com or trust.jobylon.com: no model or feature changelog, no AI incident or complaint channel, and no drift or fairness monitoring for the AI Matcher.

    Have a URL that disputes this?→

Customer Documentation

6 items60

§ 05 - Editorial notes

§ Regulatory frame

What applies to ats-integrated ai.

Ranking features are inside EU AI Act Annex III §4 (high-risk) and inside NYC Local Law 144 when they affect NYC-based candidates. Customers should treat the AI surface as a distinct deployer-FRIA scope from the rest of the ATS.

§ Others rated in ATS-integrated AI

All ats-integrated vendors→

Ranked 33 of 77 by weighted total under rubric v1.0. The ordering is arithmetic on the rubric and carries no view on which tool suits a given hiring process.

  1. 30Workable48F
  2. 31Employment Hero48F
  3. 32VidCruiter48F
  4. 33JobylonThis profile48F
  5. 34isolved47F
  6. 35Teamtailor47F

Conflicts of interest

No vendor pays for placement, scoring, or removal. Casework - the consulting firm that operates this directory - provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.

Casework has no commercial relationship with this vendor.