BerriBot Trust Center

A candidate's face, voice and ID are the most sensitive data a company will ever hold about someone who does not work there yet. This page covers how we protect that data: the frameworks and certifications we hold ourselves to, the controls we run every day, and the documents your security team can request.

How we think about security

Posture

Secure by default.

Industry-standard encryption for data at rest and in transit, role-based access controls, and per-feature data minimisation — each product feature processes only the data its job requires, nothing more.

Data stewardship

Your candidates' data stays yours.

Data residency stated in writing, India included. Zero-retention terms with our model providers. A retention schedule with published deletion timelines, and deletions that are logged and verified.

Fair by design

No black boxes in hiring decisions.

Every candidate is scored against the same written rubric with the transcript quoted under each score. No emotion, personality or mood inference from face or voice. Human review before any decision that goes against a candidate.

Transparency

What we say is what we sign.

The commitments on this page match the ones in our DPA and security documentation, and the paperwork behind every framework below is available to your security team on request.

Compliance

The frameworks below cover information security, privacy law on three continents, and AI fairness — and the documentation behind each one is available to your security team on request.

SOC 2 Type II

Trust Services Criteria covering security, availability and confidentiality. Reports are shared with your security team under NDA.

ISO 27001

Information Security Management System controls implemented across the platform — access, change, incident and vendor management.

GDPR

EU General Data Protection Regulation. Lawful bases documented per data type, explicit consent for biometrics, data subject rights honoured on request.

CCPA / CPRA

California privacy law. Disclosure, deletion and opt-out rights supported through the same request channel as GDPR.

India DPDP Act, 2023

Digital Personal Data Protection Act. Consent, purpose limitation and data principal rights built into the platform; a DPDP-ready data processing agreement is available today.

EU AI Act · ISO/IEC 24027

AI fairness and bias assessment. Bias mitigation through re-weighting, adversarial debiasing and fairness-aware training, with a bias audit summary available on request.

The controls we run

A summary of the technical and organisational controls in operation today, across security, privacy and AI fairness.

Access security

Role-based access control with least-privilege defaults
Access scoped by role — HR teams see assessments, not raw data stores
Contractual safeguards with every party that touches candidate data

Data protection

Industry-standard encryption for data at rest and in transit
Default retention of 30 days after the recruitment activity completes
Extended retention, up to 120 days, only on written client instruction
Backups and logs purged within 90 days of primary deletion
All deletions logged and verified by the security and compliance team

AI fairness and explainability

One written rubric per role — every candidate scored against the same one
No emotion, personality or mood inference from face or voice
Bias mitigation per ISO/IEC 24027: re-weighting, adversarial debiasing, fairness-aware training
Explainable AI logs and a full audit trail for every interview
Human-in-the-loop fallback, always, before adverse decisions

Candidate rights

Candidates told in advance that AI runs their interview, with an adjustments route
Explicit consent for biometric data, or a documented employment-law basis
Verified deletion requests processed within 30 days
Regulators and candidates can request fairness and validation documentation
Questions security teams ask

Direct answers, closed by default

Where does candidate data live?+

Data residency is stated in writing for every deployment, India included. Residency and the region each data type rests in are named in the DPA rather than left to inference.

How long do you keep candidate data?+

30 days after the recruitment or assessment activity completes, by default. A client can instruct retention of up to 120 days in writing for audit or compliance purposes. After deletion, backups and logs are purged within 90 days.

How is biometric data handled?+

Face, voice and ID data is processed with explicit consent, or under employment and social-protection law where that applies. Candidates are told before the interview that verification will run, and there is an adjustments route for those who need one.

Can a candidate have their data deleted?+

Yes. Verified deletion requests sent to support@berribot.com are processed within 30 days, except where a legal or contractual obligation requires continued retention — and every deletion is logged and verified.

Is our data used to train models?+

We hold zero-retention terms with our model providers, and each product feature processes only the data its specific job requires.

What certifications and frameworks do you work against?+

SOC 2 Type II and ISO 27001 for information security, GDPR, CCPA/CPRA and India's DPDP Act for privacy, and the EU AI Act with ISO/IEC 24027 for AI fairness. The reports and documentation behind each are shared with your security team on request, most under a mutual NDA.

Talk to our security team

Vendor reviews, DPA questions, audit documentation, or a candidate data request — write to us and a human answers.

support@berribot.com