Security & Compliance
At Aeviya, security and data protection are our top priorities. We implement industry-leading practices to keep your data safe.
Data Security
We employ multiple layers of security to protect your data:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3
- Encryption at Rest: All sensitive data is encrypted in our databases using AES-256 encryption
- Secure Infrastructure: Hosted on AWS with VPC isolation, security groups, and network access controls
- Regular Security Audits: Third-party penetration testing and vulnerability assessments
- Access Controls: Role-based access control (RBAC) and multi-factor authentication (MFA)
Compliance
Aeviya is committed to meeting industry standards and regulations:
- GDPR: Full compliance with EU General Data Protection Regulation
- SOC 2 Type II: Annual audits for security, availability, and confidentiality (in progress)
- CCPA: Compliance with California Consumer Privacy Act
- Equal Employment Opportunity: We design processes and monitoring to support fair hiring; employers remain responsible for lawful selection procedures. See Hiring AI compliance.
Data Privacy
Your data privacy is paramount:
- Data Ownership: You own your data. We never sell or share it with third parties
- Data Retention: Configurable retention policies to meet your compliance requirements
- Data Portability: Export your data at any time in standard formats
- Right to Deletion: Request deletion of candidate data at any time
- Candidate Consent: Built-in consent management for GDPR compliance
AI Ethics & Bias Prevention
We take fairness and measurement seriously; claims are reviewed against internal evidence where applicable:
- Monitoring: Processes to review model and flag outputs for disparate patterns where data supports analysis
- Job-related criteria: Evaluation aligned to employer-defined role requirements where configured
- Human oversight: Employers make hiring decisions; integrity signals are not a substitute for fair process
- Data governance: Training and evaluation datasets are documented with known limitations
- Non-discrimination in inputs: Scoring does not use protected characteristics as inputs; lawful audit programs are separate and restricted
Infrastructure Security
Our infrastructure is built with security in mind:
- AWS Cloud: Hosted on AWS with 99.99% uptime SLA
- DDoS Protection: CloudFlare and AWS Shield for DDoS mitigation
- Database Security: Encrypted RDS instances with automated backups
- Secrets Management: AWS Secrets Manager for secure credential storage
- Container Security: Hardened Docker containers with minimal attack surface
- Monitoring: 24/7 security monitoring and alerting
Incident Response
We have a comprehensive incident response plan:
- 24/7 Monitoring: Real-time security monitoring and alerting
- Response Team: Dedicated security team for incident handling
- Notification: We notify affected customers within 72 hours of any data breach
- Post-Incident Review: Thorough analysis and remediation after any incident
Employee Security
Our team follows strict security protocols:
- Background Checks: All employees undergo background checks
- Security Training: Regular security awareness training for all staff
- Principle of Least Privilege: Employees only have access to data they need
- NDA & Confidentiality: All employees sign non-disclosure agreements
Security Questions?
If you have security questions or need to report a vulnerability, please contact us:
Email: security@aeviya.com
For bug bounty and responsible disclosure information, please email us at the address above.
Last updated: October 20, 2025