Home / Security

Security and privacy

Watching for cheating without treating people like suspects

Integrity monitoring only works if it is fair. Trueyy is built to be honest with candidates and strict with their data. We tell people what is happening, we protect what we collect, and we give your team full control over all of it.

GDPR alignedSOC 2 in progressEncrypted by defaultConsent-first

Consent before anything

Every candidate sees a clear note about what Trueyy monitors before the interview starts. Nothing is hidden, and consent is part of the flow rather than buried in fine print.

Encrypted end to end

Session data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is scoped so only the people who should see a session can open it.

Compliance ready

Trueyy is built around GDPR and SOC 2 expectations, with consent prompts, audit logging, and retention windows you set to match your own policy.

The meeting video stays in your call

The live meeting video feed stays inside Zoom, Meet, or Teams — we don't tap it. Trueyy captures device signals, periodic screen context, and interview audio for integrity analysis; what we capture is encrypted and deleted on the retention window you set.

You control retention

Your organization sets how long session data lives. Configure per-team retention windows and delete individual sessions on request at any time.

Candidate review path

Candidates who believe a flag was incorrect can request a formal review. The process is documented and runs through your HR team, not ours.

Our principles

Five rules we will not bend on

Consent comes first. No candidate is monitored without knowing about it in plain language.
Collect only what matters. We read integrity signals, not a candidate's whole life.
You own your data. Export it, delete it, or set it to expire on a schedule you choose.
No black-box verdicts. Every flag is explained, so a human always makes the final call.
Security is not a feature. It is the floor we build everything else on top of.
Data handling at a glance
Encryption in transit (TLS 1.2+) and at rest (AES-256)
Role-based access and full audit trails
Configurable retention and one-click deletion
Data processing agreement available on request
Meeting video stays in your call; captured signals expire on your schedule
Technical and organisational measures

How we protect the data we handle

Access control

JWT authentication with refresh-token rotation, role-based access, and least-privilege API keys. Every data query is scoped to the owning company, so tenants never see each other's data.

Encryption

TLS in transit and encryption at rest across the database and file storage. Network access is restricted to an explicit allowlist.

Consent enforcement

Capture is hard-gated on candidate consent and stops automatically on revoke, session end, or a lapsed heartbeat — enforced in code, not just policy.

Accountability

An immutable audit log records privileged and data actions, giving you and us a tamper-evident trail.

Your data rights

Configurable retention with automated deletion, plus company-directed candidate erasure — permanently removing a person's captured data on request.

Sub-processors

A small, vetted set of providers, each receiving only the data it needs. See the full sub-processor register.

Have a security question we did not cover?

The team is happy to walk your security and legal stakeholders through how Trueyy handles data, consent, and incident response.