Skip to main content

Purpose

How Exterview protects your data and controls access. This page describes posture, not implementation detail. We’ve organized this page by security posture, an at a glance summary, certifications, and FAQs.

Security posture

Access & authentication

Single sign-on via your identity provider; system access via credentials scoped to your organization.

Role-based access control

Permissions scoped by role. Configure, run, and review are separate.

Encryption

Data encrypted in transit and at rest.

Environment separation

Sandbox and production are isolated from each other.

Data separation

Your data, configuration, and scoring are kept separate from other customers’.

Audit logging

Actions and results are logged for traceability.

At a glance

Certifications

Legal obligation marks a law, not a certification. Exterview claims no certification or compliance attestation against it. Full status, scope, and evidence access are on the Compliance FAQs page.
Detailed security documentation and current reports are available to customers and prospects under NDA. Contact your Exterview representative.

FAQs

Yes. Your data, configuration, and scoring are kept separate from other customers’.
Through roles and permissions scoped to your organization, following least privilege.
Yes, under NDA. Ask your Exterview representative for the current pack.