SOC 2 Type II ready. Full audit trail. Candidate consent on every assessment.
Beaverhand has completed an internal SOC 2 readiness assessment: security controls are built and mapped to the Trust Services Criteria - covering data handling, access controls, encryption, incident response, and availability. The Type II observation window has not yet been completed, so no audit report is available today.
For agencies placing at enterprise clients, SOC 2 Type II is often a procurement requirement. We can walk your security reviewer through our controls and how they map to each criterion - request our security overview at security@beaverhand.com.
| Law | Jurisdiction | Requirement | Beaverhand |
|---|---|---|---|
| Illinois AI Video Interview Act | Illinois | Disclosure + consent + deletion | ✓ Compliant |
| NYC Local Law 144 | New York City | Independent bias audit + notice | In review |
| EEOC AI Hiring Guidance | Federal | No disparate impact | Monitoring |
| Maryland AEIA | Maryland | Disclosure required | ✓ Compliant |
| Colorado SB 205 | Colorado | Algorithmic accountability | In review |
AES-256 at rest. TLS 1.3 in transit. Never sold or shared between customers.
Role-based access. SSO (SAML 2.0) for Enterprise. Shareable links are view-only.
12 months default. Custom policies for Enterprise. Early deletion on request.
Candidate or agency can request deletion at any time. Completed within 30 days.
Every assessment action logged. Full history available for compliance review.
Disclosure and explicit consent collected before every assessment begins.