Your data, protected by design

Alva Labs handles sensitive candidate and company data every day. Security is built into the platform from the ground up. ISO 27001-certified, GDPR-compliant, and audited by DNV.

Committed to responsible information security and privacy

Alva’s comprehensive information security and privacy management system is independently verified by a certification body according to international standards, reflecting our commitment to data integrity and user trust. Our ISO 27001 certification underscores our dedication to top-tier data protection regulations and security compliance.

certificates_1

Privacy by design

Service built to ensure your candidates' privacy

Best in class encryption

Rigorous processes including third party encryption key management

Annual penetration testing

Alva's platform is security vetted by experts once per year

Privacy & security documentation

certified-responsible-AI

Certified Responsible AI

Alva Labs is among the first companies in the world to be certified according to ISO/IEC 42001 – the first international standard for management systems that ensure the secure and reliable development, governance, and operation of AI.

Learn more
ISO-27001-certified

ISO 27001 certified

Validation of our commitment to information security and privacy, fostering a culture of ongoing security enhancements.

Learn more
GDPR

GDPR

At Alva Labs, we have evaluated all processing activities to ensure the correct data relationship.

Learn more
security-privacy-practices

Security & Privacy Practices

Alva Labs has a dedicated security team in place working to handle any issues that may arise within the software.

Learn more
data-retention

Data retention

Alva Labs truly cherishes the rights of the candidate and strives to create the best candidate experience.

Learn more
candidate-sign-up-flow

Candidate sign up flow

This is the experience your candidates can expect when using Alva's assessments in your hiring process.

Learn more
subprocessors

Subprocessors

A data processor is a third-party data processor engaged by Alva who has or potentially will have access to.

Learn more

“For us, it has been important to find a way of working that makes recruitment more fair, more accurate, and less dependent solely on CVs, without compromising on our requirements for security and compliance. Alva has become an important part of that work.”

Sofia Lindén Falkenlöw, HR-Specialist & Team Lead TA, Post- och telestyrelsen (PTS)

Sofia-Linden-Falkenlow-Post-och-telestyrelsen

Information security

How do you protect sensitive data from unauthorized access or breaches?

What encryption methods do you use to secure user data?

How long do you retain user data, and what is your data retention policy?

Can you provide examples of how you handle user data anonymization or pseudonymization?

What measures do you have in place to prevent data leaks or unauthorized access by employees or insiders?

What are your authentication and access control mechanisms?

User privacy & consent

What steps do you take to ensure the privacy of my personal information?

Are there any third-party subprocessors involved in handling user data, and how do you ensure their security and privacy practices?

Can I delete my personal data from your system, and how can I do that?

Do you comply with relevant privacy regulations, such as GDPR or CCPA?

How do you handle user consent and provide transparency regarding data collection and usage?

Do you share or sell user data to third parties?

Security features & certifications

What measures do you have in place to ensure the security of my personal information?

Do you conduct regular security audits or assessments?

What is your policy on data breaches, and how do you handle them?

What security features do you have in place to protect against malware or phishing attacks?

Are there any specific security certifications or standards that you adhere to?

How do you handle user authentication and password security in the platform?

How do you handle requests for access, correction, or deletion of personal information?

Questions about security or privacy?

We're happy to walk through our security practices with your team.