Trust and compliance
Candidate data protected end to end
Novexhire handles resumes, interview video, and scoring evidence for thousands of candidates a week. Here is exactly how that data is stored, who can reach it, and which auditors check our work.
SOC 2 Type II
Audited annually by an independent CPA firm across the security, availability, and confidentiality trust services criteria. The current report and bridge letter are available under NDA.
ISO 27001
Our information security management system is certified to ISO 27001, with annual surveillance audits, a maintained risk register, and documented incident response runbooks.
GDPR
Novexhire acts as processor for customer hiring data. A DPA with standard contractual clauses is available, and candidate access, correction, and erasure requests are completed within 30 days through privacy@novexhire.com.
CCPA
California candidates can request access to or deletion of their personal information at privacy@novexhire.com. We do not sell or share personal information, and we honor opt-out signals.
Controls
What is actually in place.
Reviewed annually by an independent auditor. The SOC 2 Type II report and penetration test summary are available under NDA.
Encryption everywhere
TLS 1.3 protects data in transit and AES-256 protects data at rest, including interview video, audio, transcripts, and scorecards. Encryption keys are rotated on a fixed schedule and managed separately from application infrastructure.
Role-based access
Least privilege is the default. Recruiter, hiring manager, and admin roles are scoped per requisition, and access reviews run quarterly with automatic revocation on offboarding.
SSO and MFA
SAML and OIDC single sign-on works with Okta and other identity providers, with SCIM provisioning available. Multi-factor authentication is mandatory on every Novexhire employee account.
EU data residency
Customer and candidate data for EU hiring can be pinned to EU-hosted infrastructure. US and EU regions are isolated, and cross-region transfer requires an explicit customer configuration.
Immutable audit logging
Every agent action, score change, permission grant, and export is written to an append-only audit log retained for 24 months. Logs stream to your SIEM over webhook or API.
Retention and deletion
Candidate records follow the retention window you set, defaulting to 24 months. Deletion requests remove records from primary storage, search indexes, and backups within 30 days.
Model governance
No customer or candidate data is used to train foundation models. Prompts, scoring rubrics, and model versions are versioned, change-logged, and reviewable, so any past decision can be reconstructed.
Bias testing
Adverse impact analysis runs quarterly on scoring outputs across every active rubric. An independent auditor reviews the results annually, aligned to NYC Local Law 144 requirements.
Model governance
How the scoring itself is audited.
Hiring is a high stakes decision, and the EU AI Act classifies employment systems as high risk for good reason. Our position is straightforward. Agents gather evidence and produce scores, people make decisions. No candidate at Novexhire is advanced or rejected by a model acting alone, and every outcome carries the name of the recruiter who approved it.
We test the models the way an auditor would. Each agent is evaluated before release against a held-out set of past reqs, and selection rates are checked by race, ethnicity, and sex using the four-fifths rule that underpins EEOC guidance. An independent firm audits our scoring tools every year in line with NYC Local Law 144, and we publish the summary results along with the candidate notice language our U.S. clients are required to provide. Every agent ships with a model card covering data sources, evaluated tasks, known limitations, and version history.
Candidate data is handled under GDPR and CCPA based on where the candidate sits, not only where the client sits. Interview video and audio are retained for 12 months by default, transcripts and scores for 24 months, both configurable down to 30 days and deleted within 30 days of a verified request. Access controls, encryption, and change management are covered by our SOC 2 Type II report, available under NDA from security@novexhire.com. Questions about a specific candidate record go to privacy@novexhire.com.
Reporting a vulnerability
We run a coordinated disclosure program. Send findings to security@novexhire.com. We acknowledge within one business day and will not pursue action against good-faith research.
Security review
Send us your vendor questionnaire.
We answer security reviews in-house, usually within three business days, and we will not hide behind a portal.
Or call +1 (512) 555-0142 — Austin, TX