Vervoe

Security and trust at Vervoe

Security is fundamental to how Vervoe operates. We are ISO 27001 certified and protect customer and candidate data with encryption, strict access controls, and regular independent security audits. Our data privacy practices are designed to safeguard sensitive information across its lifecycle.

A shielded checkmark hovering above a tablet, representing Vervoe's data protection and security practices
Tennis AustraliaDentsuRentokilBOQ GroupAustralia PostLumen TechnologiesKrollFindexTennis AustraliaDentsuRentokilBOQ GroupAustralia PostLumen TechnologiesKrollFindex

Certifications and frameworks we hold ourselves to

ISO 27001:2022

We're ISO 27001:2022 certified - the international standard for information security management systems - covering how we manage, protect, and continuously improve the security of customer and candidate data.

GDPR

Our data processing practices, incident response plans, and privacy policies are built to meet GDPR requirements for organizations handling personal data from the EU.

US Data Privacy

We align with US data privacy frameworks covering how personal information is collected, used, stored, and protected across the Vervoe platform.

EU AI Act

Vervoe's AI models and scoring practices are built with the EU AI Act's requirements for transparency, human oversight, and fairness in automated decision-making in mind.

Continuously monitored, independently audited

Vervoe’s security posture is monitored continuously across five control categories, covering 124 individual controls in total.

Infrastructure security

22 controls

  • Policy on the use of cryptographic controls
  • Key management
  • Electronic messaging

Organizational security

31 controls

  • Inventory of assets
  • Ownership of assets
  • Return of assets

Product security

7 controls

  • System security testing
  • Access control to program source code
  • Secure development policy

Internal security procedures

55 controls

  • Information backup
  • Planning information security continuity
  • Implementing information security continuity

Data and privacy

9 controls

  • Classification of information
  • Labelling of information
  • Handling of assets

See every control

All 124 controls are tracked live on our Trust Center, each with its current pass/fail status and last-checked time.

View all controls

What data we collect — and what we don’t

Vervoe’s database and file storage are encrypted at rest with AES-256, and every connection to our platform is protected with TLS 1.3 in transit. Servers run on AWS, with data sovereignty options in the US, EU, or Australia regions.

  • Customer personally identifiable informationCollected
  • Employee personally identifiable informationCollected
  • Credit card informationNot collected
  • Personal health informationNot collected
  • GDPR special category dataNot collected

Who else touches your data

View the full subprocessor list →

Amazon Web Services

Hosting & Infrastructure

United States / Europe / Australia

Cloud hosting platform.

Hubspot

CRM

United States

Marketing automation and customer relationship management.

Slack

Internal Communication

United States

Organizational communication platform.

Ziggeo

Video Recorder / Transcoder

United States

Facilitates and processes video assessment responses.

Common questions from security and procurement teams

Have more questions about how we protect your data?

Our full Trust Center has live control status, compliance documents, and our complete subprocessor list — request access to anything you need for a security review.