XML 46 R30.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Our board of directors recognizes the critical importance of maintaining the trust and confidence of our users, customers, clients, business partners, and employees. We are committed to protecting the privacy of our users and safeguarding our systems, networks, and services against cybersecurity risks, such as loss, unauthorized access, or other misuses.
We take that responsibility very seriously and our processes are intended to maintain high standards of governance. Our board of directors provides oversight of risk management issues, including information security and data privacy, and considers cybersecurity an important component of our overall approach to enterprise risk management, or ERM. The audit committee of our board of directors is regularly updated by management and reviews cybersecurity and other information technology risks, controls, and procedures as it deems appropriate.
Our cybersecurity policies, standards, processes, and practices reflect our business and risks, take into account recognized frameworks (such as those established by the National Institute of Standards and Technology, the International Organization for Standardization, and other applicable industry standards), and are reviewed and updated based on the specific requirements of our business. This does not imply that we meet any particular technical standards, specifications, or requirements, only that we take into account these frameworks as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
In general, we address cybersecurity risks through a cross-functional approach that is focused on preserving the confidentiality, integrity, security, and availability of the information that we collect and store and by taking steps to proactively identify, prevent, and mitigate cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
Risk Management and Strategy
As one of the critical elements of our overall ERM approach, our cybersecurity program is focused on the following key areas:
Governance: Our board of directors’ oversight of cybersecurity risk management is supported by the audit committee of our board of directors, which regularly interacts with our ERM function, including our Chief Technology Officer, or CTO, Chief Legal Officer, or CLO, and other members of management and the relevant security, privacy, and compliance teams.
Collaborative Approach and Implementation of Best Practices: We have implemented a cross-functional approach designed to identify, prevent, and mitigate cybersecurity threats and incidents alongside controls and procedures intended to provide for the prompt escalation of certain cybersecurity incidents so that decisions regarding the public disclosure and reporting of such incidents can be made by management in a timely manner. For example, through the AppSec Guild, we establish and promote development practices, policies, procedures, and technical designs intended to develop secure outward facing products and systems. Our Security Operations team helps to provide information technology security and oversight for corporate infrastructure and systems, and engages in cybersecurity incident response and management. Together, these groups work to establish a tiered posture intended to reflect best practices and protect us from cybersecurity threats.
Technical Safeguards: We deploy technical safeguards that are designed to protect our information systems from cybersecurity threats, which may include firewalls, intrusion prevention and detection systems, anti-malware functionality, and access controls.
Incident Response and Recovery Planning: We have established and maintain cybersecurity incident response policies and procedures, and business continuity and disaster recovery plans.
Third-Party Risk Management: We maintain a risk-based approach designed to identify and oversee cybersecurity risks presented by certain third parties, including vendors, service providers, and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a cybersecurity incident affecting those third-party systems.
Ongoing Employee Training: We provide regular, mandatory security awareness training and phishing simulation for our employees regarding cybersecurity threats as a means designed to equip our personnel with effective tools to identify and address cybersecurity threats.
Additional information on our policies, procedures, and safeguards can be found in our Security and Compliance webpage (https://www.ziprecruiter.global/en/security).
We engage in the periodic assessment and testing of our policies, standards, processes, and practices that are designed to address cybersecurity threats and incidents, as appropriate. These efforts may include a wide range of activities, including audits, assessments, tabletop exercises, threat modeling, vulnerability testing, and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning. For example, ZipRecruiter previously completed a third-party SOC 2 Type 2 audit, works with independent security researchers through its private bug bounty program, and conducts annual penetration testing using a third-party security tester. In addition, we use external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security processes.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Our board of directors recognizes the critical importance of maintaining the trust and confidence of our users, customers, clients, business partners, and employees. We are committed to protecting the privacy of our users and safeguarding our systems, networks, and services against cybersecurity risks, such as loss, unauthorized access, or other misuses.
We take that responsibility very seriously and our processes are intended to maintain high standards of governance. Our board of directors provides oversight of risk management issues, including information security and data privacy, and considers cybersecurity an important component of our overall approach to enterprise risk management, or ERM. The audit committee of our board of directors is regularly updated by management and reviews cybersecurity and other information technology risks, controls, and procedures as it deems appropriate.
Our cybersecurity policies, standards, processes, and practices reflect our business and risks, take into account recognized frameworks (such as those established by the National Institute of Standards and Technology, the International Organization for Standardization, and other applicable industry standards), and are reviewed and updated based on the specific requirements of our business. This does not imply that we meet any particular technical standards, specifications, or requirements, only that we take into account these frameworks as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
In general, we address cybersecurity risks through a cross-functional approach that is focused on preserving the confidentiality, integrity, security, and availability of the information that we collect and store and by taking steps to proactively identify, prevent, and mitigate cybersecurity threats and effectively responding to cybersecurity incidents when they occur.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Our board of directors, in coordination with our audit committee, oversees our ERM, including the management of risks arising from cybersecurity threats. Our audit committee receives regular presentations and reports on cybersecurity, privacy, and compliance, which may address a wide range of topics including recent developments, evolving standards, the threat environment, technological trends, and information security considerations arising with respect to our peers and third parties. Our audit committee also receives information regarding certain cybersecurity incidents.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Our CTO is primarily responsible for assessing and managing our material risks from cybersecurity threats. Our CTO has served in various roles in information technology for over 25 years, including serving as the CTO of two large companies, and holds a master’s degree in Computer Science. Our CTO works collaboratively with our Security Operations team, AppSec Guild, and VP, Corporate Counsel to implement a program designed to protect our information systems from cybersecurity threats and to respond to cybersecurity incidents in accordance with our incident response and recovery plans.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Our board of directors, in coordination with our audit committee, oversees our ERM, including the management of risks arising from cybersecurity threats. Our audit committee receives regular presentations and reports on cybersecurity, privacy, and compliance, which may address a wide range of topics including recent developments, evolving standards, the threat environment, technological trends, and information security considerations arising with respect to our peers and third parties. Our audit committee also receives information regarding certain cybersecurity incidents.
Cybersecurity Risk Role of Management [Text Block] Our CTO is primarily responsible for assessing and managing our material risks from cybersecurity threats. Our CTO has served in various roles in information technology for over 25 years, including serving as the CTO of two large companies, and holds a master’s degree in Computer Science. Our CTO works collaboratively with our Security Operations team, AppSec Guild, and VP, Corporate Counsel to implement a program designed to protect our information systems from cybersecurity threats and to respond to cybersecurity incidents in accordance with our incident response and recovery plans. To facilitate the success of our cybersecurity risk management, multidisciplinary teams throughout our company are utilized to address cybersecurity threats and to respond to cybersecurity incidents. Through ongoing communications with these teams, our Security Operations team monitors the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time and reports such threats and incidents to our Legal Team when appropriate.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Our CTO is primarily responsible for assessing and managing our material risks from cybersecurity threats. Our CTO has served in various roles in information technology for over 25 years, including serving as the CTO of two large companies, and holds a master’s degree in Computer Science. Our CTO works collaboratively with our Security Operations team, AppSec Guild, and VP, Corporate Counsel to implement a program designed to protect our information systems from cybersecurity threats and to respond to cybersecurity incidents in accordance with our incident response and recovery plans.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our CTO has served in various roles in information technology for over 25 years, including serving as the CTO of two large companies, and holds a master’s degree in Computer Science.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] Our board of directors, in coordination with our audit committee, oversees our ERM, including the management of risks arising from cybersecurity threats. Our audit committee receives regular presentations and reports on cybersecurity, privacy, and compliance, which may address a wide range of topics including recent developments, evolving standards, the threat environment, technological trends, and information security considerations arising with respect to our peers and third parties. Our audit committee also receives information regarding certain cybersecurity incidents.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true