You verify before you trust. We built for it.
Your data stays yours.
In plain terms
No training on your identifiable data
Model improvement uses anonymized, aggregated data
You control retention, residency, and deletion
Certifications are the floor. Not the finish line.
Government-grade, by authorization.
325+ NIST 800-53 controls.
FedRAMP Moderate, assessed against more than 325 NIST 800-53 controls by an accredited third party and monitored continuously.
The bar we meet for federal agencies extends to commercial customers.
Security designed in, not bolted on.
Defense in depth from the network edge to the individual data object. Access is checked at the boundary, before any business logic runs.
Defense in depth
Identity & access
Encryption
Authorization at the boundary
Multi-tenant isolation
Proven each release. Fixed on the clock.
from validated finding
from validated finding
from validated finding
from validated finding
Automated authorization testing
Runs continuously against a defined permission truth table.
Penetration testing
Independent testing, mapped to OWASP.
Secure development lifecycle
Security review built into how we ship.
Monitoring
Continuous monitoring and anomaly detection across the environment.
Responsible disclosure
Our bug bounty program gives researchers a safe way to test.
Resilience & recovery
Replicated infrastructure, secured backups, tested continuity plan.
AI that supports decisions. People make them.
The same rigor as our infrastructure: a certified management system, published bias audits, and human judgment in the loop.
Your data stays yours. Down to who touches it.
Access runs on least privilege and need to know, governed by role, and transparent to the teams who sign off on it.
Data residency
Stored in the region you choose, with controls against unintended cross-region processing
Sub-processor transparency
Your rights
A Data Processing Addendum, privacy notice, and clear data-subject-rights processes cover access, correction, and deletion.
Least privilege
Access by role and need to know; privileged support access is time-bound, approval-based, and logged.
Bulk-access guardrails
Rate limiting and monitoring help prevent authorized users from extracting data at scale.
Personnel & endpoints
Employees use secured, managed devices to keep customer data protected and controlled.
Everything your review needs. In one place.
Start with the public materials. Request gated artifacts through the Trust Portal. No NDA to get going.
Security, in our engineers' own words.
Answers for security, legal, and procurement.
Does Eightfold use my data to train its AI models?
No. The Eightfold platform does not use identifiable customer data to train its models. Model improvements use anonymized, aggregated data, never personal, identifiable information.
Is Eightfold FedRAMP authorized?
Yes. The Eightfold platform holds FedRAMP Moderate authorization, assessed against more than 325 NIST 800-53 controls and monitored continuously.
Is Eightfold SOC 2 and ISO certified?
Yes. SOC 2 Type II and ISO/IEC 27001, 27017, 27701, and 42001. Reports and certificates are in the Trust Portal.
Where is my data hosted and stored?
On AWS, with regional data residency. Controls guard against unintended cross-region processing, so data stays within contractual and regulatory boundaries.
Who can access my data?
Access follows least-privilege and need-to-know, governed by role. Privileged support access is time-bound, approval-based, and logged.
Does Eightfold comply with GDPR and the EU AI Act?
Eightfold maintains GDPR compliance and Data Privacy Framework alignment, and governs the AI Interviewer for EU AI Act readiness. A DPA and privacy notice are publicly available.
How quickly does Eightfold fix security issues?
On published timelines: critical within 48 hours, high within 30 days, medium within 90, and low within 180.
How does Eightfold reduce bias in AI-driven interviews?
The AI Interviewer supports human decisions; it does not make hiring decisions. Eightfold uses techniques designed to reduce bias against protected classes and publishes independent bias-audit results under NYC Local Law 144.
How do I run a security review of Eightfold?
Start with the public materials on this page. Request the SOC 2 report, penetration-test summary, and pre-answered questionnaires through the Trust Portal. No NDA to begin.
What should a security or legal team ask an AI interviewer vendor?
Ask about data-training use, hosting and residency, access controls, certifications (SOC 2, ISO, FedRAMP), published bias-audit results, incident-response timelines, and a Data Processing Addendum. Eightfold answers each on this page and in the Trust Portal.
How does Eightfold handle data retention and deletion?
You control retention. Data is deleted on request and on defined schedules, with data-subject-rights processes for access, correction, and deletion, governed by the Data Processing Addendum.
What contract terms does Eightfold offer?
A Data Processing Addendum and Master Services Agreement are publicly available. The DPA covers data handling, sub-processors, and data-subject rights.
How can I verify Eightfold's bias-reduction claims
Eightfold publishes independent bias-audit results under NYC Local Law 144. Review them directly rather than take the claim on faith.