Compliance & Security

Built for the legal reality of AI hiring in 2026.

SOC 2 Type II certified. Compliant with Illinois AIVIA, NYC Local Law 144, and EEOC guidance. Candidate consent built into every assessment.

SOC 2 Type II
Candidate consent built in
Full audit trail

AI hiring law compliance

Illinois AI Video Interview Act✓ Compliant
Illinois · Disclosure + consent + audit
NYC Local Law 144✓ Compliant
New York City · Bias audit + notice
EEOC AI Hiring Guidance✓ Compliant
Federal · No disparate impact
Maryland AEIA✓ Compliant
Maryland · Disclosure required
Colorado SB 205In review
Colorado · Algorithmic accountability

What SOC 2 Type II means for your agency

Direct answer

SOC 2 Type II certification means an independent auditor has verified that Beaverhand's security controls — including data handling, access controls, and encryption — operate effectively over time, not just at a single point.

The audit covers security, availability, and confidentiality. It evaluates how assessment data is stored, who can access it, how it's encrypted, and how incidents are handled. For agencies placing at enterprise clients, SOC 2 Type II is often a procurement requirement — Beaverhand passes it.

Request the full audit report: security@beaverhand.com

Candidate consent flow

1

Candidate receives the assessment link with a clear description of what they're about to complete.

2

Before starting, they see a disclosure explaining: what data is collected, how AI is used, and how results are shared.

3

Candidate provides explicit consent via checkbox before the assessment begins.

4

Consent record is stored with a timestamp and linked to the assessment session for audit purposes.

Data handling

Retention

Assessment data retained for 12 months by default. Custom retention policies available for Enterprise.

Deletion

Candidates can request deletion of their data. Agencies can delete assessment records at any time.

Access controls

Role-based access. Only authorized team members see assessment results. Shareable links are view-only.

Encryption

Data encrypted at rest (AES-256) and in transit (TLS 1.3). No assessment data is used to train AI models.

1

Connect

Set up your agency account. Invite your team. Configure role templates.

2

Consent

Every candidate sees a clear disclosure and provides consent before starting.

3

Assess

Run assessments knowing your workflow is compliant and auditable.

Frequently asked questions

Beaverhand · Built for non-technical recruiters

Run your first technical assessment in under 10 minutes.

From $50 to start. No subscription. SOC 2 Type II certified.