XOR
XOR is a text-first conversational-AI recruiting platform that pre-screens and scores high-volume and hourly candidates with recruiter-defined knockout/scoring questions over SMS, WhatsApp, and Messenger, then auto-schedules interviews on the recruiter's calendar.
HireAIScore rates XOR 30 out of 100 (grade F, Substantial gaps) under rubric v1.0, last reviewed July 17, 2026. XOR ranks 91 of 92 vendors rated in Screening AI, against a category average of 47. That score is drawn from 18 evidence items across 7 rubric criteria for XOR — 11 with a cited source, 7 recording that nothing was located.
§ 01 - Company facts
- Legal name
- XOR Inc.
- Founded
- 2016
- Headquarters
- United States · US
- Pricing tier
- Mid
- Market side
- Employer-side (AEDT)
- Categories
- ScreeningScheduling
- Website
- xor.ai
These are company details, not findings. They are editable by a verified representative and carry no weight in the score, which is built only from the cited evidence below.
§ 02 - Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%20
+4.0 · category avg 50
- 02
Bias Audit Transparency
Weight 18%18
+3.2 · category avg 46
- 03
FRIA Support
Weight 15%25
+3.8 · category avg 32
- 04
Data Governance Disclosure
Weight 15%42
+6.3 · category avg 54
- 05
Human Oversight Design
Weight 12%40
+4.8 · category avg 56
- 06
Post-Market Monitoring
Weight 12%33
+4.0 · category avg 40
- 07
Customer Documentation
Weight 8%48
+3.8 · category avg 58
Category avg is the mean raw score on that criterion across the 92 Screening AI vendors in scope of this rubric, this one included.
§ 03 - Strongest · weakest
Strongest category
Customer Documentation
Raw score 48 · contributes 3.8 to total.
48 against a 58 category average
Weakest category
Bias Audit Transparency
Raw score 18 · contributes 3.2 to total.
18 against a 46 category average
§ 04 - Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
Evidence ledger
- Items
- 18
- Documentation
- 8
- Public statement
- 3
- Absence
- 7
- With a source URL
- 11 of 18
- Source hostnames
- 1
- Fewest items
- 2
- Bias Audit Transparency
These figures measure how thoroughly XOR was reviewed, not how XOR performed — an absence row, recording that nothing was located, is counted like any other item.
Article 11 Technical Documentation
3 items20
- AbsenceCaptured Jul 17, 2026
No AI model card, technical documentation pack, explainability statement, AI policy, or ISO 42001 was found across xor.ai product pages, /privacy, /terms-and-conditions, /who-we-are, or web search.
- DocumentationCaptured Jul 17, 2026
Screening page describes recruiters choosing questions and assigning scores so candidates 'qualify themselves' but gives no scoring methodology, model documentation, or explainability.
- Public statementCaptured Jul 17, 2026
Company page shows ISO 27001, Veracode, and GDPR badges (information-security/privacy, not AI technical documentation) and no responsible-AI framework.
Bias Audit Transparency
2 items18
- AbsenceCaptured Jul 17, 2026
No bias audit or LL 144 AEDT audit summary was found on xor.ai or via web search; XOR does not reference or link any independent fairness/bias audit.
- DocumentationCaptured Jul 17, 2026
Privacy policy contains no mention of algorithmic bias testing, adverse-impact analysis, or fairness auditing.
FRIA Support
2 items25
- AbsenceCaptured Jul 17, 2026
No Fundamental Rights Impact Assessment template, EU AI Act deployer guidance, or high-risk-system obligation material found on xor.ai or in search.
- DocumentationCaptured Jul 17, 2026
Privacy policy covers GDPR and Standard Contractual Clauses for data transfers but contains no EU AI Act or fundamental-rights impact content.
Data Governance Disclosure
3 items42
- DocumentationCaptured Jul 17, 2026
Privacy policy names sub-processors (Elucru Inc., Microsoft Azure, Twilio) and describes Standard Contractual Clauses, GDPR data-subject rights, and breach handling; retention 'may store Data indefinitely' at client direction.
- Public statementCaptured Jul 17, 2026
Site footer displays ISO 27001, Veracode, and GDPR compliance badges (self-asserted, with no downloadable certificate or trust portal).
- AbsenceCaptured Jul 17, 2026
No dedicated security page (xor.ai/security returns HTTP 404), no SOC 2, no ISO 42001, and no statement of what data is used or excluded for training AI models.
Human Oversight Design
3 items40
- DocumentationCaptured Jul 17, 2026
Recruiters choose the screening questions and assign the scores that candidates qualify against, and then 'focus on Applicants that make it through XORbot's selection process'- control over criteria but no stated human review of outcomes.
- DocumentationCaptured Jul 17, 2026
Scheduling is candidate self-serve within recruiter-defined availability; page markets a 'fully automated recruiting process' with no mention of override, audit logs, or human checkpoints.
- AbsenceCaptured Jul 17, 2026
No documented human-in-the-loop requirement, override/appeal mechanism, audit-trail, in-interface explainability, or per-jurisdiction control was found.
Post-Market Monitoring
3 items33
- DocumentationCaptured Jul 17, 2026
Privacy policy provides a privacy@xor.ai contact and a data-breach notification procedure (within 7 business days, or 72 hours under GDPR).
- Public statementCaptured Jul 17, 2026
Footer references Veracode security scanning, implying periodic vulnerability testing, but no continuous public monitoring surface.
- AbsenceCaptured Jul 17, 2026
No public status page, model-update changelog, incident-disclosure channel, or continuous-monitoring dashboard found on xor.ai.
Customer Documentation
2 items48
- DocumentationCaptured Jul 17, 2026
Public Terms and Conditions and Privacy Policy cover GDPR, data-subject rights, and sub-processors, but reference no separate Data Processing Agreement, LL 144 notice, or compliance guidance.
- AbsenceCaptured Jul 17, 2026
No deployer/compliance guidance, published DPA, NYC Local Law 144 candidate-notice template, or EU AI Act customer guidance found on xor.ai.
§ 05 - Editorial notes
Company overview
XOR (XOR Inc.) is a US recruiting-automation vendor founded in 2016 by Aida Fazylova and Nikolay Manolov and headquartered in San Jose, California. Its XORbot chatbot engages applicants over SMS, WhatsApp, and Messenger to pre-screen, score, and self-schedule them, and is aimed squarely at high-volume hourly and blue-collar hiring in sectors such as healthcare, retail, and staffing. Recruiters configure the screening questions and assign scores so candidates 'qualify themselves,' and the platform integrates with 20+ ATS/HRIS systems including Bullhorn, Greenhouse, Lever, and SAP SuccessFactors while marketing a low cost-per-hire, text-first hiring funnel.
Regulatory exposure
XOR's chatbot scores and filters applicants against recruiter-defined thresholds, which makes it an Automated Employment Decision Tool under NYC Local Law 144 and a high-risk employment system under the EU AI Act. Despite this, XOR publishes no bias audit, no model/system card, no AI policy or explainability statement, and no NYC- or EU-specific deployer guidance. Its footer displays self-asserted ISO 27001, Veracode, and GDPR badges, and the privacy policy names sub-processors (Elucru Inc., Microsoft Azure, Twilio) and Standard Contractual Clauses, but there is no ISO 42001, SOC 2, dedicated security/trust page (xor.ai/security returns 404), or Fundamental Rights Impact Assessment material. Deployers therefore carry direct LL 144 and EU AI Act obligations with very little vendor-supplied evidence to rely on.
Path to a higher score
XOR could raise its score fastest by commissioning and publicly posting an independent NYC LL 144 bias audit (e.g., BABL AI, Warden AI, or Holistic AI) and publishing an AI/system model card with an explainability statement describing how scores are produced. Standing up a dedicated security/trust page (SOC 2 or ISO 42001 plus a training-data / data-exclusion statement), documenting concrete human-in-the-loop, override, and audit-log controls, adding EU AI Act deployer guidance and a FRIA template, and opening a public status/changelog and security-disclosure channel would move XOR from a marketing-only posture to defensible, citable compliance documentation.
§ Regulatory frame
What applies to screening ai.
Treated as high-risk under Annex III §4 when the screening output is decisive. EU AI Act Article 13 transparency obligations apply; deployers must give candidates a way to contest.
§ Compare
Build any comparison→XOR against its nearest-scoring peers.
In Screening AI.
§ Others rated in Screening AI
All screening vendors→Ranked 91 of 92 by weighted total under rubric v1.0. The ordering is arithmetic on the rubric and carries no view on which tool suits a given hiring process.
- 88Zappyhire34F
- 89Entelo33F
- 90Moonhub30F
- 91XORThis profile30F
- 92Mercor23F
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework - the consulting firm that operates this directory - provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.