Security
Security and control for every interview
Protect candidate and interview data with role-based access, consent records, audit history, privacy workflows, and human review for AI-assisted output.
Security controls
Workspace controls at a glance.
Controls
Review the controls that protect your workspace
See how Itya manages administrative activity, privacy requests, AI-assisted output, and connected systems.
Audit history
Review interview, scorecard, billing, security, and administrative activity with workspace context.
Privacy requests
Manage candidate data exports, deletion requests, consent records, and legal-hold review.
Human review for AI output
Verify AI-assisted debriefs against cited transcript moments before they are shared.
Integration visibility
Connect scheduling and recruiting systems with clear connection and health states.
In depth
Controls across the data lifecycle
Access controls
Workspace roles, session security, two-factor authentication, and administrative boundaries keep access explicit.
Data lifecycle
Candidate consent, privacy requests, audit exports, legal holds, and deletion workflows stay visible to administrators.
AI and integrations
Debriefs preserve source citations and review states, while integration health makes connection status clear.
Security practices
Practical safeguards for interview data
Review the safeguards available today, or contact our security team for more detail on how candidate and workspace data is handled.
- Encryption in transit, and at the storage layer
Traffic is served over TLS 1.2/1.3 with HSTS. The database volume and the object store the deployment runs on are encrypted by the hosting platform.
- Application-level encryption for credentials
Integration OAuth tokens, ATS and webhook signing secrets, Slack tokens and two-factor secrets are additionally sealed with AES-256-GCM under versioned keys. Candidate records, résumés, transcripts, scorecards and audit payloads are not column-encrypted unless field-level encryption is switched on for the deployment.
- Role-based access control
Workspace roles scope what members, admins, and owners can see and change.
- Audit logging
Interview, scorecard, billing, security, and admin actions are recorded with actor context.
- GDPR data requests
Candidates can request a data export or deletion through a public, verified workflow.
- Session controls
Two-factor authentication, session review, and sign-out of active sessions per user.
- Data export and deletion
Workspace data can be exported, and deletion requests follow defined timelines.
Get started