Security & data protection
How Interscreening protects your candidate data — without marketing jargon.
Hosting & data sovereignty
Verity runs entirely within the European Union (Netherlands). No data transfer to third countries under Schrems II risk. Backups remain in the EU. Sub-processors are limited to infrastructure explicitly operating under the GDPR.
Encryption
- At rest: AES-256 for all personal data and report content.
- In transit: TLS 1.3 (minimum 1.2), HSTS, no mixed content.
- Secrets: 2FA secrets and magic-link tokens are stored encrypted or as SHA-256 hashes — never in plaintext.
GDPR — privacy by design
- Data minimisation (Art. 5(1)(c)): only fields the report requires.
- Storage limitation (Art. 5(1)(e)): configurable retention per organisation. Completed screenings are automatically anonymised after the configured number of days (minimum 30, typically 365).
- Right to be forgotten: anonymisation preserves psychometric norm data (anonymised, no longer linkable to a person) so instrument validity is not destroyed.
- Anonymous invitations: token-based access for anonymous group measurements without PII. K-anonymity threshold of at least 5 respondents per group prevents re-identification.
Access control
- Five-layer role hierarchy (Super Admin > Admin > HR Manager > Manager > User), strictly enforced on every route.
- Mandatory 2FA (TOTP) for all admin roles.
- Magic-link login (15-minute tokens, single-use) for candidates — no passwords in circulation.
- Account lock-out after 10 failed login attempts.
Audit trail
Every significant action is recorded in an independent audit log: login (success/failure), 2FA events, role changes, data exports, anonymisations. Searchable by tenant admins.
Accessibility
The platform is built on WCAG 2.1 AA. Skip links, ARIA roles, keyboard navigation, contrast ratios — not optional additions but part of the design.
Compliance & standards
- GDPR (EU 2016/679)
- ISO 27001 aligned (information-security management controls)
- WCAG 2.1 AA (accessibility)
- OWASP Top-10 risk mitigations (CSP headers, CSRF protection, validation at system boundaries)
Security audit log
Tenant admins have direct access to a security audit log within the platform: magic-link issuance, 2FA events, role changes. On escalation, Interscreening can share additional incident data on request to support your incident response.
Sub-processors
Interscreening uses a limited set of sub-processors (all EU-based or verified under GDPR). The full list including processing purpose and jurisdiction is available on request to customers and their data protection officers.
Data processing agreement
A GDPR-compliant data processing agreement is included with every subscription. Your legal team can request the draft via the contact form.
Questions about security?
Our technical lead is happy to help your security and compliance team.