Security & Compliance

At Aeviya, security and data protection are our top priorities. We implement industry-leading practices to keep your data safe.

Data Security

We employ multiple layers of security to protect your data:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3
  • Encryption at Rest: All sensitive data is encrypted in our databases using AES-256 encryption
  • Secure Infrastructure: Hosted on AWS with VPC isolation, security groups, and network access controls
  • Regular Security Audits: Third-party penetration testing and vulnerability assessments
  • Access Controls: Role-based access control (RBAC) and multi-factor authentication (MFA)

Compliance

Aeviya is committed to meeting industry standards and regulations:

  • GDPR: Full compliance with EU General Data Protection Regulation
  • SOC 2 Type II: Annual audits for security, availability, and confidentiality (in progress)
  • CCPA: Compliance with California Consumer Privacy Act
  • Equal Employment Opportunity: We design processes and monitoring to support fair hiring; employers remain responsible for lawful selection procedures. See Hiring AI compliance.

Data Privacy

Your data privacy is paramount:

  • Data Ownership: You own your data. We never sell or share it with third parties
  • Data Retention: Configurable retention policies to meet your compliance requirements
  • Data Portability: Export your data at any time in standard formats
  • Right to Deletion: Request deletion of candidate data at any time
  • Candidate Consent: Built-in consent management for GDPR compliance

AI Ethics & Bias Prevention

We take fairness and measurement seriously; claims are reviewed against internal evidence where applicable:

  • Monitoring: Processes to review model and flag outputs for disparate patterns where data supports analysis
  • Job-related criteria: Evaluation aligned to employer-defined role requirements where configured
  • Human oversight: Employers make hiring decisions; integrity signals are not a substitute for fair process
  • Data governance: Training and evaluation datasets are documented with known limitations
  • Non-discrimination in inputs: Scoring does not use protected characteristics as inputs; lawful audit programs are separate and restricted

Infrastructure Security

Our infrastructure is built with security in mind:

  • AWS Cloud: Hosted on AWS with 99.99% uptime SLA
  • DDoS Protection: CloudFlare and AWS Shield for DDoS mitigation
  • Database Security: Encrypted RDS instances with automated backups
  • Secrets Management: AWS Secrets Manager for secure credential storage
  • Container Security: Hardened Docker containers with minimal attack surface
  • Monitoring: 24/7 security monitoring and alerting

Incident Response

We have a comprehensive incident response plan:

  • 24/7 Monitoring: Real-time security monitoring and alerting
  • Response Team: Dedicated security team for incident handling
  • Notification: We notify affected customers within 72 hours of any data breach
  • Post-Incident Review: Thorough analysis and remediation after any incident

Employee Security

Our team follows strict security protocols:

  • Background Checks: All employees undergo background checks
  • Security Training: Regular security awareness training for all staff
  • Principle of Least Privilege: Employees only have access to data they need
  • NDA & Confidentiality: All employees sign non-disclosure agreements

Security Questions?

If you have security questions or need to report a vulnerability, please contact us:

Email: security@aeviya.com

For bug bounty and responsible disclosure information, please email us at the address above.

Last updated: October 20, 2025