Skip to content
Back to Intervio
Security and trust

Private hiring records deserve deliberate controls.

A concise account of the safeguards in Intervio today—and the limits customers should understand.

Effective August 4, 2026 · Version 1.0

Current safeguards

Workspace access

Recruiter review routes require signed-in, approved workspace access. Candidate invitations use time-limited, single-use tokens.

Encryption

Production web traffic uses HTTPS/TLS. Stored recordings use Amazon S3 server-side encryption, and the production database and its provider-managed backups are encrypted at rest.

Private full-recording playback

A guarded route verifies the signed-in hiring-team member and workspace before issuing short-lived access to a private recording. Storage credentials are never published.

Private evidence sharing

Shared evidence requires verification of the invited email address and is limited to one external recipient. Access lasts up to 14 days and can be revoked. The shared brief includes selected answer clips, the summary, and conversation transcript. It does not include the full interview recording.

Limited internal access

Intervio limits personnel access to an operational need. Candidate-consent, invitation, interview, delivery, and administrative workflow events retain bounded audit histories.

Verified provider events

Live-video and email provider callbacks are verified before lifecycle or delivery state is applied, and duplicate events are handled idempotently.

Recording lifecycle

Private recordings expire after 30 days and are not copied into a separate Intervio recording backup. Explicit candidate deletion requests are processed sooner.

Location, recovery, and incidents

The production application, database, and recording store are in Virginia, United States. Real-time media and AI services can use provider-operated global infrastructure. Managed database backups are encrypted and follow the provider's backup schedule; interview recordings are not duplicated into a separate Intervio backup.

If an incident affects candidate data, Intervio will investigate, contain it, and notify affected hiring companies without undue delay where law or contract requires notification.

Service processing

Security is shared: hiring teams must protect accounts and invitation links, and candidates should use a trusted device and network. The named providers that help operate Intervio are listed on the Subprocessor page.

What this page does not claim

This overview is not a certification, audit report, guarantee against every incident, or claim that automated evaluation is scientifically validated or free from bias. Hiring teams must apply human judgment and their own legal, security, accessibility, and procurement requirements.

Report a concern

Email support@intervio.ai with “Security report” in the subject. We aim to acknowledge a responsible report within three business days.

Do not include passwords, secret keys, full recordings, or more candidate information than needed. Intervio will not pursue legal action for good-faith research that avoids privacy harm, service disruption, extortion, and public disclosure before we have had a reasonable opportunity to respond.