Skip to content

Security

Security and control for every interview

Protect candidate and interview data with role-based access, consent records, audit history, privacy workflows, and human review for AI-assisted output.

Security controls

Workspace controls at a glance.

Consent captureActive
Audit exportReady
AI review gateRequired
Provider healthHealthy
09:14AdminExported audit log for security review.
09:22SystemAI debrief approval required before sharing.

Controls

Review the controls that protect your workspace

See how Itya manages administrative activity, privacy requests, AI-assisted output, and connected systems.

Audit history

Review interview, scorecard, billing, security, and administrative activity with workspace context.

Privacy requests

Manage candidate data exports, deletion requests, consent records, and legal-hold review.

Human review for AI output

Verify AI-assisted debriefs against cited transcript moments before they are shared.

Integration visibility

Connect scheduling and recruiting systems with clear connection and health states.

In depth

Controls across the data lifecycle

Access controls

Workspace roles, session security, two-factor authentication, and administrative boundaries keep access explicit.

Data lifecycle

Candidate consent, privacy requests, audit exports, legal holds, and deletion workflows stay visible to administrators.

AI and integrations

Debriefs preserve source citations and review states, while integration health makes connection status clear.

Security practices

Practical safeguards for interview data

Review the safeguards available today, or contact our security team for more detail on how candidate and workspace data is handled.

  • Encryption in transit, and at the storage layer

    Traffic is served over TLS 1.2/1.3 with HSTS. The database volume and the object store the deployment runs on are encrypted by the hosting platform.

  • Application-level encryption for credentials

    Integration OAuth tokens, ATS and webhook signing secrets, Slack tokens and two-factor secrets are additionally sealed with AES-256-GCM under versioned keys. Candidate records, résumés, transcripts, scorecards and audit payloads are not column-encrypted unless field-level encryption is switched on for the deployment.

  • Role-based access control

    Workspace roles scope what members, admins, and owners can see and change.

  • Audit logging

    Interview, scorecard, billing, security, and admin actions are recorded with actor context.

  • GDPR data requests

    Candidates can request a data export or deletion through a public, verified workflow.

  • Session controls

    Two-factor authentication, session review, and sign-out of active sessions per user.

  • Data export and deletion

    Workspace data can be exported, and deletion requests follow defined timelines.

Get started

Bring your security team into the evaluation

Contact us to review access controls, privacy workflows, and AI-assisted output before your trial.