Security & Trust
Assessment data handled with the seriousness it deserves.
Candidate data is sensitive — it determines careers. This page describes how AssessIQ protects that data, how we approach India's evolving data protection landscape, and what controls we apply to keep assessments fair and results trustworthy.
A note on certifications: AssessIQ describes security practices and design intent — not third-party certification status. We do not hold SOC 2, ISO 27001, or equivalent certifications at this time. We will update this page if and when that changes. Buyers who require a specific certification as a procurement condition should ask us directly about our roadmap.
Data protection
How candidate data is protected.
Data protection & DPDP Act awareness
Designed with India's data protection law in mind.
India's Digital Personal Data Protection (DPDP) Act 2023 places obligations on how personal data is collected, processed, and stored. AssessIQ is built to support those obligations: candidate data is collected only for the purpose of assessment, processing is scoped to that purpose, and we aim to give data principals — candidates — meaningful control over their data. We continue to monitor DPDP rulemaking as it matures.
Data residency
Candidate data stays in India.
All assessment data, candidate records, proctoring footage, and attempt logs are stored on India-region infrastructure. We do not route personal data through overseas servers for routine processing. This matters for institutions and employers who need to demonstrate that candidate information remains within Indian jurisdiction.
Encryption in transit and at rest
TLS everywhere. Data encrypted at rest.
All traffic between candidates, administrators, and AssessIQ is encrypted in transit using TLS 1.2+. Sensitive data — including candidate PII and assessment responses — is encrypted at rest in the underlying database. Access credentials are never stored in plaintext.
Multi-tenant isolation
Your data is never visible to another organisation.
AssessIQ is a multi-tenant platform. Each company or institution operates in a fully isolated tenant context enforced at the database layer through row-level security policies. Admins from one organisation cannot see, search, or export data belonging to another. Candidate data is scoped to the organisation that ran the assessment.
Audit logging
Every action is logged and auditable.
AssessIQ maintains append-only audit logs for all administrative actions: assessment creation and publication, candidate invitations, result access, and configuration changes. Logs are timestamped and cannot be modified or deleted by administrators. Enterprise customers can export full audit trails for internal compliance review.
Access controls
Role-separated access across the platform.
The platform enforces strict role separation: super-admins, company administrators, reviewers, and candidates each see only what their role permits. Reviewer access to candidate answers is scoped by assignment — a reviewer can see only the assessments they are assigned to. Admin credentials require email-based multi-factor authentication.
Assessment integrity
Fair tests. Trustworthy results.
Proctoring
Full proctoring (Growth and Enterprise tiers) combines browser lockdown — candidates cannot switch tabs or open other applications — with webcam monitoring. Suspicious events are flagged automatically and surfaced to administrators for review. Every flag is accompanied by a timestamp and a screenshot or recording clip.
Anti-cheat measures
Question packs support randomisation of question order and, for MCQ, answer option order. Time limits are enforced server-side, not only in the browser. Copy-paste is restricted in the coding environment. These measures reduce the value of answer-sharing between candidates in the same drive.
Fairness & bias mitigation
AssessIQ uses anchor-based, rubric-driven scoring rather than subjective judgment. Every assessment outcome carries rationale — what the candidate demonstrated, and at which band. This makes the basis for a score inspectable and challenges to it addressable. Question packs can be reviewed for language neutrality before deployment.
Answer-key protection
Correct answers and scoring rationale are never exposed to candidates — not in the assessment UI, not in share links, and not in any API response that a candidate can reach. Access to correct answers is gated to administrator and reviewer roles only.
Infrastructure
How the platform is built.
Traffic through Cloudflare.
All inbound traffic to AssessIQ is routed through Cloudflare before it reaches the origin server. This provides DDoS mitigation, TLS termination, and an additional layer between the open internet and candidate data. Direct-origin access is blocked at the network layer.
Containerised, isolated services.
The platform runs as a set of containerised services. The candidate-facing application, the admin application, the API layer, and the database run in separate containers with scoped network access. A vulnerability in the candidate UI does not give access to the admin API.
Dependency management.
AssessIQ's technology stack is maintained with security updates as a routine part of development — not an afterthought. Dependencies are kept current; known critical CVEs are resolved before they reach production.
Questions about our security posture?
If you have specific data-protection or compliance requirements — DPDP obligations, internal audit questions, or procurement checklists — reach out. We'll give you a straight answer, including where our current posture does and does not meet your bar.
See how it applies to your context