Trust & Security
Security and trust at Vervoe
Security is fundamental to how Vervoe operates. We are ISO 27001 certified and protect customer and candidate data with encryption, strict access controls, and regular independent security audits. Our data privacy practices are designed to safeguard sensitive information across its lifecycle.















Compliance
Certifications and frameworks we hold ourselves to
ISO 27001:2022
We're ISO 27001:2022 certified - the international standard for information security management systems - covering how we manage, protect, and continuously improve the security of customer and candidate data.
GDPR
Our data processing practices, incident response plans, and privacy policies are built to meet GDPR requirements for organizations handling personal data from the EU.
US Data Privacy
We align with US data privacy frameworks covering how personal information is collected, used, stored, and protected across the Vervoe platform.
EU AI Act
Vervoe's AI models and scoring practices are built with the EU AI Act's requirements for transparency, human oversight, and fairness in automated decision-making in mind.
Security controls
Continuously monitored, independently audited
Vervoe’s security posture is monitored continuously across five control categories, covering 124 individual controls in total.
Infrastructure security
22 controls
- Policy on the use of cryptographic controls
- Key management
- Electronic messaging
Organizational security
31 controls
- Inventory of assets
- Ownership of assets
- Return of assets
Product security
7 controls
- System security testing
- Access control to program source code
- Secure development policy
Internal security procedures
55 controls
- Information backup
- Planning information security continuity
- Implementing information security continuity
Data and privacy
9 controls
- Classification of information
- Labelling of information
- Handling of assets
See every control
All 124 controls are tracked live on our Trust Center, each with its current pass/fail status and last-checked time.
Data handling
What data we collect — and what we don’t
Vervoe’s database and file storage are encrypted at rest with AES-256, and every connection to our platform is protected with TLS 1.3 in transit. Servers run on AWS, with data sovereignty options in the US, EU, or Australia regions.
- Customer personally identifiable informationCollected
- Employee personally identifiable informationCollected
- Credit card informationNot collected
- Personal health informationNot collected
- GDPR special category dataNot collected
Subprocessors
Who else touches your data
Amazon Web Services
Hosting & Infrastructure
United States / Europe / Australia
Cloud hosting platform.
Hubspot
CRM
United States
Marketing automation and customer relationship management.
Slack
Internal Communication
United States
Organizational communication platform.
Ziggeo
Video Recorder / Transcoder
United States
Facilitates and processes video assessment responses.
Trust & security FAQ
Common questions from security and procurement teams
Yes. Vervoe's database of customer data, along with our S3 buckets, are encrypted at rest using AES-256.
Yes. Vervoe uses TLS 1.3 everywhere data is transmitted over networks, along with features such as HTTPS to maximize the security of data in transit.
Vervoe's servers are located in AWS, with options for data sovereignty in the US, EU, or Australia regions.
Yes. Vervoe engages an external penetration testing consulting firm at least annually. All areas of the Vervoe product and cloud infrastructure are in scope for these assessments, and source code is made fully available to the testers to maximize coverage.
Vervoe creates a unique AI model for each customer, trained exclusively on a dataset generated by that customer's own users manually grading responses. Every past grade is visible in the app along with who assigned it, and admins can flag or override incorrect grades to maximize dataset integrity. Vervoe also undergoes annual independent audits to assess for bias.
Vervoe uses an open-source Data Processing Addendum (DPA). Reach out to compliance@vervoe.com to have it attached to your contract.
Have more questions about how we protect your data?
Our full Trust Center has live control status, compliance documents, and our complete subprocessor list — request access to anything you need for a security review.
