Eightfold.ai Trust Portal

# Welcome to Eightfold's Trust Portal **Security, compliance, and transparency at every level.** Eightfold.ai combines AI-powered recruiting, talent intelligence, and workforce transformation to help enterprises hire, retain, and grow smarter. We believe trust is earned through transparency—that's why our Trust Portal gives you complete visibility into our security posture, compliance certifications, responsible AI practices, and subprocessor ecosystem. *Questions about our security, compliance, or responsible AI practices?* Contact our Security & Compliance team at [security@eightfold.ai](mailto:security@eightfold.ai)

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Eightfold.ai Trust Portal
Header background

Eightfold.ai Trust Portal

Welcome to Eightfold's Trust Portal

Security, compliance, and transparency at every level.

Eightfold.ai combines AI-powered recruiting, talent intelligence, and workforce transformation to help enterprises hire, retain, and grow smarter. We believe trust is earned through transparency—that's why our Trust Portal gives you complete visibility into our security posture, compliance certifications, responsible AI practices, and subprocessor ecosystem.

Questions about our security, compliance, or responsible AI practices? Contact our Security & Compliance team at security@eightfold.ai

Compliance and assurance

Independent certifications and assessments provide evidence that security, privacy, and AI governance practices are formally managed.

ISO/IEC 27001 certification

The information security management system supporting the Talent Intelligence Platform is certified against ISO/IEC 27001:2022. The certified scope covers relevant operational, engineering, product, support, legal, finance, human resources, and security functions.

ISO/IEC 27701 certification

The privacy information management system supporting the Talent Intelligence Platform is certified against ISO/IEC 27701:2019. The scope explicitly includes responsibilities for processing personally identifiable information.

ISO/IEC 42001 certification

The artificial intelligence management system supporting the Talent Intelligence Platform is certified against ISO/IEC 42001:2023. The scope includes the functions responsible for developing, operating, supporting, and governing AI systems.

Data protection

Documented safeguards protect customer and candidate information throughout transmission, storage, processing, and model development.

Encryption in transit

Customer system integrations are secured during transmission. This reduces the risk of unauthorized interception while candidate and recruiting information moves between systems.

Encryption at rest

Customer integration data is secured when stored in databases and files. This helps protect information if unauthorized access to underlying storage is attempted.

Training data anonymization

Raw resumes used in model training are stripped of direct identifiers and transformed into feature representations without identifiers. The documented analysis reports that nearly all training vectors have multiple close neighbors, reducing the risk of singling out an individual.

Privacy management

Privacy controls support responsible processing, retention, deletion, and customer administration of personal information.

Customer-controlled data management

Customer data entered or uploaded to the platform is managed by the customer. This supports customer accountability and control over information processed through the service.

Data retention governance

Customer data is retained according to contractual commitments and applicable internal retention and deletion policies. This provides a defined basis for managing how long customer information is kept.

Administrator data deletion

Administrators have user-friendly capabilities to locate and take action on candidate data, including deletion of candidate profiles. This supports privacy requests and customer-managed lifecycle processes.

Data synchronization control

Integrations with customer systems enable customers to manage control over data synchronization. This helps customers govern how information is exchanged with connected systems.

AI governance

Formal governance practices promote accountable, transparent, and responsible development and operation of AI systems.

Artificial intelligence management system

An AI management system is implemented and certified against ISO/IEC 42001:2023. This establishes a formal governance structure for AI-related activities within the documented scope.

Human-centered AI governance

Responsible AI practices are supported by cross-functional stakeholders, an AI Ethics Council, and external consultants. These governance participants contribute to the responsible design and deployment of AI systems.

Human oversight of employment decisions

The matching model and AI Interviewer are designed to support human decision-makers rather than make hiring decisions automatically. Recruiters or customer administrators remain responsible for reviewing information and determining next steps.

AI transparency and explainability

Users receive understandable explanations of match scores and their relationship to job requirements, including skills, experience, work, and title relevance. This helps customers evaluate AI-supported recommendations and communicate their basis to stakeholders.

Fairness and bias mitigation

Multiple safeguards evaluate and reduce the risk of discriminatory outcomes across protected groups and individual candidate profiles.

Protected characteristic exclusion

The matching model does not use protected characteristics such as gender, age, or ethnicity as model features. This limits the direct use of sensitive attributes in candidate matching.

Candidate masking

Candidate masking can remove sensitive information from resumes before recruiter review, including names, gender indicators, race or ethnicity, disability, religion, and contact information. This helps focus evaluation on job-related skills and experience.

Bias and adverse impact analysis

The organization measures group-level outcomes using fairness metrics such as impact ratios, selection rates, and statistical performance measures. These analyses support identification of disparate outcomes across gender, race, and intersectional groups.

Individual fairness testing

Perturbation testing compares model scores for original and modified resumes where demographic or other sensitive signals are changed. This provides a documented method for testing whether those changes materially affect matching outcomes.

Independent bias audits

Annual independent third-party bias audits are conducted for the matching model, with summary information released to customers. This provides external review of fairness and supports customer compliance activities.

AI model validation and monitoring

Pre-release testing and ongoing production monitoring help maintain model accuracy, stability, and fairness over time.

Pre-deployment model testing

Model updates undergo quantitative and qualitative testing, including blind evaluations of model outputs, before release. This helps identify performance or fairness issues before changes reach customers.

Continuous production monitoring

Production models are continuously monitored using measures such as prediction behavior, latency, accuracy, and fairness-related metrics. Monitoring can be analyzed across accounts, regions, roles, and other applicable groupings.

Model drift alerts

Alerts are configured to identify potential model drift or degradation when monitored values cross defined thresholds. This supports timely investigation and response to changes in production behavior.

Model remediation process

When critical degradation alerts occur, the engineering organization evaluates the root cause and remediates the issue. Model launch checks can also stop releases when defined gender-difference thresholds are exceeded.

Human-evaluated validation datasets

Production models are evaluated regularly against continually growing datasets curated through human-in-the-loop review. This provides an ongoing reference for assessing model behavior.

Application and network security assurance

Independent testing and threat-informed assessment provide external validation of application and internet-facing security controls.

Independent application security testing

An independent security firm performed third-party testing of the web application and supporting infrastructure. The engagement evaluated areas including authentication, session tracking, authorization, file handling, and input validation.

Independent external network testing

An independent security firm performed third-party testing of the external network to identify vulnerabilities that could expose sensitive business data or workflows. The assessment reported no vulnerabilities during its testing period.

Threat-informed security assessment

The documented testing methodology prioritizes vulnerabilities most likely to be exploited by criminals and combines manual analysis with automated techniques where they improve testing efficiency. The approach is aligned with recognized security and compliance frameworks.

Platform isolation and customer environments

Customer environments are provisioned as private areas within the managed platform to support separation of customer data and operations.

Private customer instances

Customer instances are provisioned as private secure areas when the contract begins. This supports separation of customer environments within the platform.

Managed platform infrastructure

The platform hosting the matching model is managed by the organization. Centralized management supports consistent operation of the platform environment and its associated security processes.

Customer data ownership and responsibility

Customer-originated data entered or uploaded by authorized customer users remains managed by the customer. This clarifies customer control and responsibilities for information handled through the platform.

Candidate privacy and consent

Candidate-facing safeguards promote informed participation, privacy choices, accessibility, and control during AI-supported interviews.

Candidate consent recording

Consent for AI interviews and required video and audio collection is obtained in advance and stored. Consent for recordings can also be collected and made available to customers when required.

Candidate transparency notices

Candidates receive advance notification when an AI interview is scheduled, along with interview guidance, frequently asked questions, and an introductory video. These measures help candidates understand the process before participating.

Human interview alternative

Customers can provide candidates with the option to interview with a human interviewer. This gives organizations a documented alternative to an AI-mediated interview.

Accessibility assistance

Candidates can request accessibility-related accommodations through the documented interview support options. This helps reduce barriers to participation in the hiring process.

AI interviewer safety and oversight

Controls governing AI-supported interviews emphasize privacy-aware interaction, evidence-based outputs, and customer review before employment actions.

Private data safeguards

The AI Interviewer measures and evaluates whether interview questions avoid requesting sensitive personal information, including health, religion, race, family status, and financial information. This supports privacy-conscious interviewing.

Evidence-grounded feedback

AI-generated interview feedback is evaluated for factual grounding, traceability to transcript evidence, and completeness. These safeguards help customers distinguish supported observations from unsupported conclusions.

Customer review of AI feedback

Customer administrators can review interview audio, transcripts, summaries, and completed feedback forms before making a decision. Candidates do not automatically advance to later stages based solely on the AI interview.

Jailbreak and misuse evaluation

The AI Interviewer is evaluated for attempts to bypass its guidelines, manipulate its behavior, or induce unauthorized responses. This testing addresses foreseeable misuse and supports safer operation.