> ## Documentation Index
> Fetch the complete documentation index at: https://docs.exterview.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance FAQs

> Status-accurate compliance answers for security and procurement reviewers evaluating Exterview: a self-serve review checklist, certifications, data handling, and vendor questions.

## Purpose

Straight answers for security and procurement reviewers, so you can assess the platform without waiting on a sales cycle. Certifications are shown with their current, accurate status.

## Self-serve review checklist

Exterview is an intelligence layer above your ATS — it evaluates candidates and produces reports; it is not your system of record. That narrows what data it needs. Work through these steps to review the platform:

<Steps>
  <Step title="Review the access model">
    Access is role-based and specific to your organization. Review the nine
    system roles and the per-module access matrix in [How to Assign Roles and
    Access](/guides/setup-roles-access).
  </Step>

  <Step title="Review data handling">
    See what data is processed, how long it is retained, and how deletion and
    consent work in [Privacy and Residency](/trust/privacy-residency).
  </Step>

  <Step title="Review the model and sub-processor posture">
    Confirm which models process data and that your data is not used to train
    shared models in [Models We Use](/trust/models), and review third parties in
    [Sub-processors](/trust/sub-processors).
  </Step>

  <Step title="Review AI governance">
    Confirm human review on adverse decisions, explainability, and disclosure in
    [Responsible AI](/trust/responsible-ai).
  </Step>

  <Step title="Review the audit trail">
    See what is logged and how changes are traced in
    [Auditability](/trust/auditability).
  </Step>

  <Step title="Check certification status">
    Review current, in-progress, and planned attestations below. Treat anything
    not listed as not yet in place.
  </Step>
</Steps>

**Controls you hold:** role-based access specific to your organization, set by you · human review on adverse decisions, which cannot be turned off · data residency and consent, configured during setup in [How to Set Compliance and Privacy](/guides/setup-compliance) · a full audit trail on privileged actions. Retention rules are still being finalized; see [Privacy & Residency](/trust/privacy-residency).

<Note>
  This checklist doesn't replace a formal security questionnaire — for that,
  work with your Exterview contact. Implementation-level security details are
  shared under review rather than published, because they can change and warrant
  legal and security sign-off.
</Note>

## Certifications & frameworks

Exterview's certification posture is shown with current, accurate status. Certifications are earned, not claimed, anything not yet held is marked in progress.

| Standard              | What it covers                                       | Status                   |
| --------------------- | ---------------------------------------------------- | ------------------------ |
| ISO/IEC 27001         | Information security management system               | **In progress**          |
| SOC 2 Type II         | Security, availability, and confidentiality controls | **In progress**          |
| ISO/IEC 42001         | AI management system                                 | **In progress**          |
| GDPR (EU)             | Personal data protection and candidate rights        | **Operational**          |
| DPDP Act 2023 (India) | Digital personal data protection                     | **Operational**          |
| GAMP 5                | Validation readiness for regulated / pharma pilots   | **Available on request** |

<Info>
  **Certified** means an independent audit is complete. **In progress** means
  the program is underway but not yet awarded. **Operational** means Exterview
  operates in line with the regulation (GDPR and DPDP are legal obligations, not
  third-party certifications). **Available on request** means Exterview can
  discuss meeting the requirement for a regulated pilot, while we finish a few
  additional requirements for regulated industries.
</Info>

<Note>
  Current certificates, audit reports, and evidence are available to customers
  and prospects under NDA, contact your Exterview representative. Exterview does
  not claim certifications it does not hold.
</Note>

## Procurement FAQs

<AccordionGroup>
  <Accordion title="Does Exterview make automated hiring decisions?">
    No. Human review applies to outcomes; no fully autonomous adverse decision is made. See [Responsible AI](/trust/responsible-ai).
  </Accordion>

  <Accordion title="How is our data processed?">
    Only to run your evaluations, scoped to your organization's data. It isn't
    sold or pooled into a shared model. See [Privacy &
    Residency](/trust/privacy-residency).
  </Accordion>

  <Accordion title="Does identity verification involve biometric data?">
    If you turn on identity verification, it works by checking a photo ID against
    a face photo. This is sensitive information, and it's handled separately from
    candidate scoring. It's used only to confirm identity, not to score a
    candidate or make any hiring decision. See [Responsible
    AI](/trust/responsible-ai).
  </Accordion>

  <Accordion title="Can data be deleted on request?">
    Yes, deletion requests are honored. We're finishing a fully centralized
    process for handling these requests consistently across all data types. See
    [Privacy & Residency](/trust/privacy-residency).
  </Accordion>

  <Accordion title="How is access restricted?">
    Roles and permissions, scoped to your organization, following least privilege.
    See [Security](/trust/security).
  </Accordion>

  <Accordion title="Are actions auditable?">
    Yes. Setup, sessions, reports, reviews, and configuration changes are traced.
    See [Auditability](/trust/auditability).
  </Accordion>

  <Accordion title="How do integrations handle data?">
    Connectors move only the data needed to run or support a workflow, under your
    governance and consent settings.
  </Accordion>

  <Accordion title="Where is our data stored?">
    In the region you select during setup, to support residency requirements.
  </Accordion>
</AccordionGroup>

## Related

<CardGroup cols={2}>
  <Card title="Security" icon="lock" href="/trust/security">
    Architecture-level security posture in more detail.
  </Card>

  <Card title="Responsible AI" icon="user-check" href="/trust/responsible-ai">
    How human review and explainability are enforced.
  </Card>
</CardGroup>
