Security

You verify before you trust. We built for it.

Enterprise and government-grade security for AI native talent intelligence. Not a checklist we passed. An architecture we publish, test continuously, and let you inspect.
No training on your identifiable data
FedRAMP Moderate authorized
325+ NIST 800-53 controls
SOC 2 Type II and four ISO certifications
48 hour vulnerability remediation from validated finding
Human in the loop, not automated hiring decisions
your data

Your data stays yours.

The Eightfold platform does not use identifiable customer data to train its models. Models improve on rigorously anonymized, aggregated data, never personal information. You decide what to share, where it lives, and when it is deleted.

In plain terms

No training on your identifiable data

Model improvement uses anonymized, aggregated data

You control retention, residency, and deletion

Compliance & certifications

Certifications are the floor. Not the finish line.

FedRAMP Moderate, ISO 42001, ISO 27001/27017/27701, and SOC 2 Type II. Independently audited, continuously renewed, each linked to its evidence.
Framework
Status
FedRAMP Moderate
Authorized
ISO 42001
Certified
ISO 27001
Certified
ISO 27017
Certified
ISO 27701
Certified
SOC 2 Type II
Attested
SOC 3
Attested
GDPR & Data Privacy Framework
Compliant
CCPA
Compliant
OFCCP
Aligned
NYC Local Law 144
Bias-audited

Government-grade, by authorization.

325+ NIST 800-53 controls.

FedRAMP Moderate, assessed against more than 325 NIST 800-53 controls by an accredited third party and monitored continuously.

The bar we meet for federal agencies extends to commercial customers.

Security architecture

Security designed in, not bolted on.

Defense in depth from the network edge to the individual data object. Access is checked at the boundary, before any business logic runs.

Defense in depth

CIS-benchmarked infrastructure behind a web application firewall; FIPS 140-2 validated encryption; VPN plus MFA for admin access

Identity & access

SSO/SAML, MFA, and role- and attribute-based access control; privileged actions logged with acting admin, target user, role, tenant, and timestamp

Encryption

TLS 1.2 or higher in transit, AES-256 at rest, secrets rotated on schedule.

Authorization at the boundary

A non-bypassable checkpoint across 2,000+ production endpoints; endpoint registry and allowlisting deny by default; object-level checks block cross-tenant access

Multi-tenant isolation

Tenant identity from the authenticated session, enforced at the data layer, fails closed; customer-managed keys supported; isolation tested continuously
Continuous assurance

Proven each release. Fixed on the clock.

Security at scale is a posture, not a project. We verify it continuously and put published timelines behind our fixes.

Automated authorization testing

Runs continuously against a defined permission truth table.

Penetration testing

Independent testing, mapped to OWASP.

Secure development lifecycle

Security review built into how we ship.

Monitoring

Continuous monitoring and anomaly detection across the environment.

Responsible disclosure

Our bug bounty program gives researchers a safe way to test.

Resilience & recovery

Replicated infrastructure, secured backups, tested continuity plan.

Secure and responsible AI

AI that supports decisions. People make them.

The same rigor as our infrastructure: a certified management system, published bias audits, and human judgment in the loop.

Governance
ISO 42001 management system; AI subsystems held inside the same permission boundaries as the platform.
Bias
Techniques designed to reduce bias against protected classes; independent bias-audit results published under NYC Local Law 144.
AI-native risks
Governance for agentic-AI threats such as prompt injection and retrieval risks, and EU AI Act readiness.
AI supply chain
Training data, embeddings, feature stores, and inference paths access-restricted and monitored like any production system.

Related reading

Privacy & data governance

Your data stays yours. Down to who touches it.

Access runs on least privilege and need to know, governed by role, and transparent to the teams who sign off on it.

Data residency

Stored in the region you choose, with controls against unintended cross-region processing

Sub-processor transparency

A current sub-processor list names each provider, purpose, and region.

Your rights

A Data Processing Addendum, privacy notice, and clear data-subject-rights processes cover access, correction, and deletion.

Least privilege

Access by role and need to know; privileged support access is time-bound, approval-based, and logged.

Bulk-access guardrails

Rate limiting and monitoring help prevent authorized users from extracting data at scale.

Personnel & endpoints

Employees use secured, managed devices to keep customer data protected and controlled.

For security reviewers

Everything your review needs. In one place.

Start with the public materials. Request gated artifacts through the Trust Portal. No NDA to get going.

Eightfold secures
You configure
Platform, infrastructure, and controls
Access, roles, and permissions within your tenant
Encryption, isolation, and monitoring
User provisioning and SSO
Certifications, audits, and patching
Data handling and retention settings
Engineering blog

Security, in our engineers' own words.

We publish how we build and defend the platform: the reasoning and the architecture, not just the certificates that result.

FROM THE ENGINEERING BLOG

Endpoint Protection Framework: Authorization and Validation at the Boundary

FROM THE ENGINEERING BLOG

Rethinking interviews: building a fair, multimodal AI Interviewer

FROM MEDIUM

A Comprehensive Guide to Securing Your Infrastructure

FAQ

Answers for security, legal, and procurement.

No. The Eightfold platform does not use identifiable customer data to train its models. Model improvements use anonymized, aggregated data, never personal, identifiable information.

Yes. The Eightfold platform holds FedRAMP Moderate authorization, assessed against more than 325 NIST 800-53 controls and monitored continuously.

Yes. SOC 2 Type II and ISO/IEC 27001, 27017, 27701, and 42001. Reports and certificates are in the Trust Portal.

On AWS, with regional data residency. Controls guard against unintended cross-region processing, so data stays within contractual and regulatory boundaries.

Access follows least-privilege and need-to-know, governed by role. Privileged support access is time-bound, approval-based, and logged.

Eightfold maintains GDPR compliance and Data Privacy Framework alignment, and governs the AI Interviewer for EU AI Act readiness. A DPA and privacy notice are publicly available.

On published timelines: critical within 48 hours, high within 30 days, medium within 90, and low within 180.

The AI Interviewer supports human decisions; it does not make hiring decisions. Eightfold uses techniques designed to reduce bias against protected classes and publishes independent bias-audit results under NYC Local Law 144.

Start with the public materials on this page. Request the SOC 2 report, penetration-test summary, and pre-answered questionnaires through the Trust Portal. No NDA to begin.

Ask about data-training use, hosting and residency, access controls, certifications (SOC 2, ISO, FedRAMP), published bias-audit results, incident-response timelines, and a Data Processing Addendum. Eightfold answers each on this page and in the Trust Portal.

You control retention. Data is deleted on request and on defined schedules, with data-subject-rights processes for access, correction, and deletion, governed by the Data Processing Addendum.

A Data Processing Addendum and Master Services Agreement are publicly available. The DPA covers data handling, sub-processors, and data-subject rights.

Eightfold publishes independent bias-audit results under NYC Local Law 144. Review them directly rather than take the claim on faith.

Certifications prove the floor. We publish the architecture behind them.

Share Popup Title

Share this article