跳至内容
Intrvio

信托中心

最后更新: 2026-04-18

Intrvio 专为结构化人工智能辅助面试而设计,其中人类仍然对招聘决策负责。本页介绍了当今可用的控制措施以及我们在销售材料中使用的合规态势。除非有签署的第三方报告或证书,否则我们不会声称获得 SOC 2、ISO 27001 或 ISO 42001 认证。

安全和隐私联系人:hello@intrvio.com

Intrvio 由 FORLYZE 有限公司

当前的准备状态

SOC 2 就绪/符合 ISO 27001

安全准备

基于角色的访问、审核日志、最低权限服务访问、加密传输、保留作业和管理员审核流程均作为产品控制实施。

GDPR / 英国 GDPR / KVKK 支持

隐私工作流程

候选人通知、DPA 支持、数据删除请求、保留设置、隐私联系人字段和子处理者透明度可供客户审核。

ISO 42001/欧盟人工智能法案准备情况

人工智能治理

GAIA 的输出是建议性的。雇主审核员在做出任何招聘决定之前会查看成绩单、评分理由和人工审核控制。

纽约市 LL144 / EEOC 导向的出口支持

公平性证据

当客户或司法管辖区需要外部验证时,偏见审计导出和审查日志可以为独立审计员提供支持。

如何阅读我们的声明

  • 已认证意味着存在当前的外部报告或证书。
  • 就绪或一致意味着产品和内部控制是围绕该框架设计的,但未声明外部认证。
  • 合规仅用于客户可配置的工作流程,雇主仍对其自身的合法使用负责。
  • 招聘决定必须由雇主的人工审核员做出,而不是由 GAIA 做出。

当前子处理者

供应商目的地区数据保护局状态
Affinda2026-04-27Candidate CV parsing and document extractionUS/EU/AU查看不活跃
ElevenLabs2026-04-27AI voice interview agent, speech processing, and interview conversation handlingUS/EU查看活跃
Meta Platforms Ireland Ltd2026-05-01WhatsApp Business Platform message routing and deliveryEU/Global查看活跃
OpenRouter2026-04-27CV parsing and optional model routing for AI analysisUS查看活跃
Resend2026-04-27Transactional email deliveryUS查看活跃
Supabase2026-04-27Database, authentication, storage, and application backend infrastructureUS/EU查看活跃
Twilio2026-05-01SMS, phone verification, and WhatsApp Business Platform messaging deliveryUS/EU查看活跃
Twilio2026-04-27SMS and phone verification deliveryUS/EU查看不活跃
Vercel2026-04-27Application hosting, edge middleware, and deployment infrastructureUS/EU查看活跃

Compliance posture

What we currently do, and what we are working on — surfaced for buyers evaluating us against EU AI Act, GDPR, SOC 2, and NYC LL144 expectations. No marketing fluff.

In production

EU AI Act

Article 26 employer obligations supported: audit log, transparency notice, region tagging, decision-record export.

AI Act page →

In production

GDPR

Data minimization, right to erasure, retention controls, EU residency option. DPA ready to sign.

DPA →

In progress

SOC 2 Type I

Target Q4 2026 — internal controls being prepared for independent attestation. Forward-looking.

Roadmap

ISO 27001

On the 2027 roadmap. Scope: Information Security Management System.

Ready

NYC LL144

Bias-audit-ready exports; independent audit pipeline documented for the four-fifths rule.

Practical guide →

Technical

Security

TLS 1.3, AES-256, MFA, SAML SSO, Cloudflare WAF, Supabase RLS, immutable audit logs.

Security page →

Data handling

Interview data flow: candidate audio is captured over an encrypted transport, encrypted at rest, transcript stored encrypted, scoring is run inline. Customer content is not used to train our own models, and is not sent to a model provider for training.

Retention: candidate audio and transcript default to 365 days, configurable down to shorter windows. Early deletion is one click and is visible in the audit log.

Active sub-processors: ElevenLabs, Meta Platforms Ireland Ltd, OpenRouter, Resend, Supabase, Twilio, Vercel. See the table below or the dedicated sub-processors page for the full list and change notifications.

Access controls

  • • SAML 2.0 SSO (Scale tier)
  • • SCIM user provisioning (Scale tier)
  • • TOTP MFA — enforceable workspace-wide
  • • Role-based access: employer, recruiter, admin
  • • Tenant isolation via Supabase RLS in Postgres

Auditing

Every interview action — start, model output, recruiter override, export, deletion — is recorded in an append-only audit log keyed by session. Logs retained for a 6-month minimum (AI Act Art. 26(6)); 12 months configurable on request.

Reporting a vulnerability

Report security issues to security@intrvio.com. 90-day responsible disclosure window. Good-faith security research is welcome and protected.

我们如何通知变更

在添加或更换任何子处理者之前,我们会提前 30 天发出通知。通知通过电子邮件发送至帐户上的计费/管理联系人,并通过 RSS 发布。客户可以在通知期内以书面形式反对新的分处理者;如果异议无法解决,客户可以终止受影响的服务。

订阅更改

要接收子处理者变更通知,请通过电子邮件订阅。我们仅将此列表用于子处理者公告。

通过电子邮件订阅

Intrvio by FORLYZE LTD · 公司编号 16937650 · 在英格兰和威尔士注册