Security & Compliance
Rigovo is built with a defense-in-depth security architecture. Every layer — from network edge to database field — enforces isolation, encryption, and audit.
End-to-End Encryption
All data encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM). Sensitive PII fields receive an additional layer of application-level encryption before storage.
Multi-Tenant Isolation
Database-level row isolation ensures each organization's data is completely separated. Even application-layer bugs cannot leak cross-tenant data.
Zero-Trust Authentication
Every endpoint requires authentication — SSO for dashboard users, time-limited tokens for candidates, and cryptographically signed keys for all internal services.
SOC2-Aligned Audit Logging
Every sensitive action is logged with actor, resource, timestamp, and full metadata. Audit trails are retained for up to 7 years for compliance.
Network-Level Protection
Enterprise WAF, DDoS protection, restrictive Content Security Policies, HSTS enforcement, and strict rate limiting across all endpoints.
Integrity Verification
Proprietary multi-signal detection engine continuously monitors interview sessions for identity fraud, AI-generated answers, and unauthorized assistance.
How We Protect Your Data
Multiple independent security layers ensure that a breach in any single layer cannot compromise your data.
Encryption at Every Layer
- TLS 1.2+ enforced on all connections with HSTS
- AES-256-GCM encryption for data at rest
- Application-level PII encryption before database write
- Encrypted media storage for all recordings
Access Control
- Enterprise SSO integration (SAML, Google, Microsoft)
- Role-based access control with granular permissions
- Time-limited, single-use tokens for candidate sessions
- Cryptographically signed internal service authentication
Network Security
- Enterprise WAF with edge-level DDoS protection
- Restrictive Content Security Policy with domain allowlisting
- Rate limiting across all API endpoints
- Security headers (X-Frame-Options, X-Content-Type-Options, HSTS)
Multi-Tenant Data Isolation
Database-Level Isolation
Your data is isolated at the database level — not just the application level. This means that even if there were a bug in our application code, it would be physically impossible for another organization's data to be returned in your queries.
- Every query executes within your organization's isolated context
- Database-enforced policies prevent cross-tenant data access
- Privileged access is audit-logged with 7-year retention
- Regular third-party penetration testing validates isolation
Interview Integrity Protection
Our proprietary Sentinel Engine continuously monitors every interview session across 15 signal types. Here's what it covers — without revealing how.
Identity Verification
Multi-factor identity checks throughout the session — not just at the start. If someone swaps in, the system flags it.
Behavioral Analysis
Continuous monitoring for behavioral anomalies, suspicious patterns, and indicators of unauthorized assistance during the interview.
Anti-Spoofing
Detection of replay attacks, synthetic speech, and deepfake attempts. Multiple layers of liveness and authenticity verification.
Detection Methodology Under NDA
The specific signals, thresholds, and detection algorithms that power our integrity engine are proprietary and shared only under NDA during the enterprise evaluation process. This protects the effectiveness of the system — if bad actors knew exactly what we look for, they could engineer around it.
Request security whitepaperTamper-Proof Forensic Trail
Cryptographic Chain Integrity
Every interview generates an append-only forensic event log with cryptographic chain hashing. Each event is linked to the previous one, making it impossible to tamper with or delete records without detection.
- SHA-256 chain hashing — each event cryptographically linked to the previous
- Chain integrity can be independently verified at any point
- Full JSON export available for compliance auditors
- Legally defensible evidence chain for hiring decisions
What Gets Logged
Comprehensive event coverage across the entire interview lifecycle:
GDPR Article 22: Every automated decision generates a structured summary with decision type, outcome, confidence score, and contributing factors.
Data Retention & Lifecycle
Plan-Based Retention
Data is automatically deleted after your plan's retention window. No manual action required.
Automated Enforcement
Retention is enforced automatically — not dependent on manual processes:
- Automated daily scans identify expired interview data
- Recordings, transcripts, identity materials, and evidence permanently removed
- Full audit trail generated for every deletion event
- Infrastructure-level lifecycle policies as an additional safety net
GDPR Compliance
Right to Erasure
Complete data anonymization on request. All recordings, transcripts, identity materials, and PII are permanently removed with a cryptographic deletion certificate.
Data Portability
Full data export in machine-readable format on request — all candidate data, assessments, and audit records.
Automated Decision Transparency
Every automated assessment generates structured decision summaries with outcome, confidence score, and contributing factors for human review.
Records of Processing
Comprehensive audit logging captures all data processing activities with retention periods of 1 to 7 years depending on category.
Audit Logging
SOC2-Aligned Logging
Every sensitive action across the platform is captured in an immutable audit log. Who did what, when, and what changed — with full metadata for compliance auditors.
Access Controls
- Role-based access control with granular permission sets
- Super admin actions require elevated authentication and are always logged
- Cross-organization access is strictly audited and time-limited
- Candidate tokens are single-use and scoped to their session only
- All API keys are cryptographically signed and scoped
Compliance Roadmap
GDPR
SOC2 Type II
ISO 27001
HIPAA
Need More Detail?
We're happy to provide our full security whitepaper, walk through our architecture under NDA, or answer any compliance questions your team may have.