Security & Compliance

Enterprise-Grade
From Day One

Built with bank-level security architecture, PIPEDA/FCRA compliance, and $1M insurance coverage. Because your screening data deserves the same protection as financial data.

AES-256
Encryption at Rest
TLS 1.3
Encryption in Transit
$1M
E&O + Cyber Coverage
99.9%
Uptime SLA
SECURITY
Active Security Measures

These protections are live and defending your data right now.

AES-256-GCM Encryption

All sensitive data encrypted at rest. Voice recordings encrypted before storage with individual encryption keys.

Active

TLS 1.3 Transport

Every connection encrypted with TLS 1.3. No data moves between systems without encryption.

Active

Session Management

Secure JWT-based sessions with automatic token refresh, expiration, and revocation on logout.

Active

Automated Backups

Enterprise PostgreSQL with continuous backups and point-in-time recovery. Your data is never at risk.

Active

Role-Based Access

RBAC with least-privilege principles. Admin, user, and API key permissions are strictly separated.

Active

24/7 Monitoring

Real-time health monitoring with automated alerting. 99.9% uptime SLA with public status page.

Active

Data Deletion

Data deletion processed within 48 hours of request. Configurable retention policies per customer.

Active

Enterprise Hosting

Professional cloud infrastructure with enterprise-grade networking, firewalls, and DDoS protection.

Active

MFA Available

Multi-factor authentication available for all accounts. Additional protection for admin-level access.

Active
PRIVACY
Privacy Protections

Built-in protections for every participant in the screening process.

AI Transparency

Our AI identifies itself immediately and explains the purpose of the call to every reference. No deception, ever.

Clear Consent

Consent obtained before any recording begins. References can opt out of calls at any time.

Two-Party Consent Compliance

Automated compliance for all two-party consent jurisdictions across Canada and the US.

Right to Deletion

Any participant can request their data or its deletion. Processed within 48 hours.

Configurable Retention

Voice recordings: 3 years. Hiring decisions: 4 years. Fully configurable to your policy requirements.

Privacy-by-Design

Data minimization principles applied throughout. We collect only what's needed for screening.

RESPONSIBLE AI
Human-in-the-Loop AI

AI assists human decision-making. It never replaces it.

Human Decision Authority

All employment decisions are made by qualified humans. AI provides structured data and insights only.

No Candidate Scoring

Our AI does not score, rate, or rank candidates as individuals. No "fit scores." No numerical rankings.

No Auto-Rejection

Candidates are never automatically disqualified. Every screening result requires human review before any action.

No Hiring Recommendations

Virvell never recommends hire/no-hire decisions. Workflow labels indicate process steps, not outcomes.

Bias Monitoring

Active monitoring for demographic bias patterns. Continuous refinement of conversational AI systems.

Read our full AI Acceptable Use Policy →
ENTERPRISE
Vendor & Infrastructure Security

Every vendor in our stack meets enterprise security standards.

SOC 2 Type II Vendors

All critical infrastructure and voice AI vendors maintain SOC 2 Type II certification with annual re-assessment.

PCI-DSS Level 1

Payment processing via Stripe meets the highest PCI-DSS security standards. No card data touches our servers.

Regular Security Audits

All vendors undergo regular third-party security assessments. We review vendor security posture annually.

Vendor Risk Assessment

Comprehensive security evaluation before any vendor is selected. No vendor touches data without passing review.

Note: Specific vendor details are available under NDA during security reviews. We don't disclose infrastructure providers publicly to maintain security best practices.

INSURANCE & RISK
Insurance & Risk Management

Comprehensive coverage that exceeds typical startup standards.

Technology E&O Insurance

$1M professional errors and omissions coverage through Tokio Marine. Protects against technology failures and professional liability.

Active

Cyber Liability Coverage

$1M cyber liability coverage including data breach response, forensic investigation, and notification costs.

Active

24/7 Incident Response

Immediate access to security and legal experts through our insurance provider's incident response network.

Active

Documented Procedures

Written incident response plan, data breach notification procedures, and business continuity documentation.

Active
DOCUMENTATION
Security Documentation

Ready for your procurement and security review process.

Security Questionnaires

3–5 business day turnaround for standard security questionnaires (SIG, CAIQ, custom).

Data Processing Agreements

DPAs available upon request, covering PIPEDA and provincial privacy requirements.

Certificates of Insurance

COIs available for contracts, RFPs, and vendor onboarding processes.

Penetration Testing

Coordinated penetration testing available for enterprise customers upon request.

Compliance Audit Support

Third-pay audit cooperation and comprehensive security documentation packages.

COMPLIANCE
Compliance Framework

Designed for Canadian and US privacy regulations from the ground up.

PIPEDA Compliant

Compliant with Canadian federal privacy law and provincial equivalents (PIPA Alberta, Quebec Law 25).

Active

US State Privacy

Designed for CCPA, CPRA, and emerging state privacy regulations. Two-party consent automation built in.

Active

FCRA via Certn

Background checks run through Certn, which handles all FCRA compliance, adverse action workflows, and dispute processes.

Active

Privacy-by-Design

Transparent consent, data minimization, purpose limitation, and configurable retention built into every workflow.

Active
ROADMAP
What We're Building Next

We're transparent about our security roadmap. Enterprise customers drive certification priorities.

Q2 2026

Real-time bias analysis dashboard for demographic fairness monitoring

Q2 2026

Enhanced DDoS protection and abuse prevention layer

Q3 2026

Dedicated Canadian infrastructure (AWS ca-central-1) for data residency

Q3 2026

Automatic data deletion based on configured retention policies

Q4 2026

Comprehensive audit logging for compliance reporting

2027

Enterprise SSO (SAML/OIDC) for larger organizations

CERTIFICATIONS
Planned Certifications

Pursuing formal certifications as we scale with enterprise customers.

SOC 2 Type II

Third-party validation of security controls and processes. Timeline driven by enterprise customer requirements.

Planned

ISO 27001

International standard for information security management systems.

Planned

Third-Party Pen Testing

Professional external security assessments with published remediation timelines.

Planned
CONTACT
Security & Privacy Inquiries

General Support

support@virvell.ai

Ready for Your Security Review?

We'll walk you through our security architecture, share documentation, and answer your team's questions. Most security reviews complete in under a week.