Skip to main content

Purpose

Straight answers for security and procurement reviewers, so you can assess the platform without waiting on a sales cycle. Certifications are shown with their current, accurate status.

Self-serve review checklist

Exterview is an intelligence layer above your ATS — it evaluates candidates and produces reports; it is not your system of record. That narrows what data it needs. Work through these steps to review the platform:
1

Review the access model

Access is role-based and specific to your organization. Review the nine system roles and the per-module access matrix in How to Assign Roles and Access.
2

Review data handling

See what data is processed, how long it is retained, and how deletion and consent work in Privacy and Residency.
3

Review the model and sub-processor posture

Confirm which models process data and that your data is not used to train shared models in Models We Use, and review third parties in Sub-processors.
4

Review AI governance

Confirm human review on adverse decisions, explainability, and disclosure in Responsible AI.
5

Review the audit trail

See what is logged and how changes are traced in Auditability.
6

Check certification status

Review current, in-progress, and planned attestations below. Treat anything not listed as not yet in place.
Controls you hold: role-based access specific to your organization, set by you · human review on adverse decisions, which cannot be turned off · data residency and consent, configured during setup in How to Set Compliance and Privacy · a full audit trail on privileged actions. Retention rules are still being finalized; see Privacy & Residency.
This checklist doesn’t replace a formal security questionnaire — for that, work with your Exterview contact. Implementation-level security details are shared under review rather than published, because they can change and warrant legal and security sign-off.

Certifications & frameworks

Exterview’s certification posture is shown with current, accurate status. Certifications are earned, not claimed, anything not yet held is marked in progress.
Certified means an independent audit is complete. In progress means the program is underway but not yet awarded. Operational means Exterview operates in line with the regulation (GDPR and DPDP are legal obligations, not third-party certifications). Available on request means Exterview can discuss meeting the requirement for a regulated pilot, while we finish a few additional requirements for regulated industries.
Current certificates, audit reports, and evidence are available to customers and prospects under NDA, contact your Exterview representative. Exterview does not claim certifications it does not hold.

Procurement FAQs

No. Human review applies to outcomes; no fully autonomous adverse decision is made. See Responsible AI.
Only to run your evaluations, scoped to your organization’s data. It isn’t sold or pooled into a shared model. See Privacy & Residency.
If you turn on identity verification, it works by checking a photo ID against a face photo. This is sensitive information, and it’s handled separately from candidate scoring. It’s used only to confirm identity, not to score a candidate or make any hiring decision. See Responsible AI.
Yes, deletion requests are honored. We’re finishing a fully centralized process for handling these requests consistently across all data types. See Privacy & Residency.
Roles and permissions, scoped to your organization, following least privilege. See Security.
Yes. Setup, sessions, reports, reviews, and configuration changes are traced. See Auditability.
Connectors move only the data needed to run or support a workflow, under your governance and consent settings.
In the region you select during setup, to support residency requirements.

Security

Architecture-level security posture in more detail.

Responsible AI

How human review and explainability are enforced.