Purpose
Straight answers for security and procurement reviewers, so you can assess the platform without waiting on a sales cycle. Certifications are shown with their current, accurate status.Self-serve review checklist
Exterview is an intelligence layer above your ATS — it evaluates candidates and produces reports; it is not your system of record. That narrows what data it needs. Work through these steps to review the platform:1
Review the access model
Access is role-based and specific to your organization. Review the nine
system roles and the per-module access matrix in How to Assign Roles and
Access.
2
Review data handling
See what data is processed, how long it is retained, and how deletion and
consent work in Privacy and Residency.
3
Review the model and sub-processor posture
Confirm which models process data and that your data is not used to train
shared models in Models We Use, and review third parties in
Sub-processors.
4
Review AI governance
Confirm human review on adverse decisions, explainability, and disclosure in
Responsible AI.
5
Review the audit trail
See what is logged and how changes are traced in
Auditability.
6
Check certification status
Review current, in-progress, and planned attestations below. Treat anything
not listed as not yet in place.
This checklist doesn’t replace a formal security questionnaire — for that,
work with your Exterview contact. Implementation-level security details are
shared under review rather than published, because they can change and warrant
legal and security sign-off.
Certifications & frameworks
Exterview’s certification posture is shown with current, accurate status. Certifications are earned, not claimed, anything not yet held is marked in progress.Certified means an independent audit is complete. In progress means
the program is underway but not yet awarded. Operational means Exterview
operates in line with the regulation (GDPR and DPDP are legal obligations, not
third-party certifications). Available on request means Exterview can
discuss meeting the requirement for a regulated pilot, while we finish a few
additional requirements for regulated industries.
Current certificates, audit reports, and evidence are available to customers
and prospects under NDA, contact your Exterview representative. Exterview does
not claim certifications it does not hold.
Procurement FAQs
Does Exterview make automated hiring decisions?
Does Exterview make automated hiring decisions?
No. Human review applies to outcomes; no fully autonomous adverse decision is made. See Responsible AI.
How is our data processed?
How is our data processed?
Only to run your evaluations, scoped to your organization’s data. It isn’t
sold or pooled into a shared model. See Privacy &
Residency.
Does identity verification involve biometric data?
Does identity verification involve biometric data?
If you turn on identity verification, it works by checking a photo ID against
a face photo. This is sensitive information, and it’s handled separately from
candidate scoring. It’s used only to confirm identity, not to score a
candidate or make any hiring decision. See Responsible
AI.
Can data be deleted on request?
Can data be deleted on request?
Yes, deletion requests are honored. We’re finishing a fully centralized
process for handling these requests consistently across all data types. See
Privacy & Residency.
How is access restricted?
How is access restricted?
Roles and permissions, scoped to your organization, following least privilege.
See Security.
Are actions auditable?
Are actions auditable?
Yes. Setup, sessions, reports, reviews, and configuration changes are traced.
See Auditability.
How do integrations handle data?
How do integrations handle data?
Connectors move only the data needed to run or support a workflow, under your
governance and consent settings.
Where is our data stored?
Where is our data stored?
In the region you select during setup, to support residency requirements.
Related
Security
Architecture-level security posture in more detail.
Responsible AI
How human review and explainability are enforced.

