Security

Last Updated:

Security Overview

Astrix processes sensitive data (voice, video, skills & communication assessments) on behalf of our users and their organisations. Protecting that data is core to our product. This overview describes the technical and organisational measures we use to keep it secure. We handle personal data in a manner designed to comply with the GDPR, and our security programme is aligned with the internationally recognised ISO/IEC 27001 information-security framework.

Our approach. We collect only the data we need, protect it in transit and at rest, restrict who can access it, monitor our systems, and hold our vendors to the same standard. Below is a plain-language summary of the controls we operate across the ISO/IEC 27001 domains.

Governance and information-security management

We maintain a set of internal information-security policies that define how we handle data, manage risk and respond to incidents. Security responsibilities are assigned to named owners, and we review our policies and risks periodically and when significant changes occur. Our practices are aligned with the ISO/IEC 27001 framework.

Core controls

Data encryption. Personal data, including recordings, transcripts and scores, is encrypted in transit using TLS and at rest using strong industry-standard encryption.

Access control and authentication. Access to systems and data is granted on a least-privilege, need-to-know basis. We require multi-factor authentication (MFA) for access to our systems, and we offer single sign-on (SSO / SAML) for organisations so they can manage their users' access through their own identity provider. Access rights are reviewed regularly.

Data minimisation and segregation. We collect only what is needed to deliver assessments, logically separate customer data, and support deletion of recordings and derived data on request.

Network and application security. Our services run on reputable cloud infrastructure with network controls, secure development practices, and regular monitoring for vulnerabilities and threats.

Monitoring and logging. We log access to sensitive systems and monitor for anomalous activity so that potential issues can be detected and investigated.

Backup and resilience. We maintain backups and operational practices designed to preserve the availability and integrity of data and to support recovery.

Handling of voice, video and biometric data

Because our Services process biometric and other sensitive data, we apply heightened care to it:

  • recordings and derived biometric metrics are treated as sensitive data throughout their lifecycle;

  • we conduct Data Protection Impact Assessments where processing is likely to result in high risk, in line with the GDPR;

  • we do not use identifiable recordings or biometric data to train general-purpose AI models without an appropriate lawful basis and, where required, explicit consent; and

  • features that infer emotion-related states are configurable and may be disabled for deployments where their use is restricted by law.

Supplier and sub-processor management

We use vetted third-party providers (for example cloud hosting, AI/speech analysis, transcription and analytics). We enter into data-processing agreements with them, require appropriate security and confidentiality commitments, and use lawful transfer mechanisms such as Standard Contractual Clauses where data crosses borders. A current list of key sub-processors is available on request.

People and process

Our team is bound by confidentiality obligations and receives security and data-protection awareness guidance. Access to production data is limited to personnel who need it for their role.

Incident response and breach notification

We maintain an incident-response process to identify, contain and remediate security incidents. Where a personal-data breach is likely to result in a risk to individuals, we will notify the relevant supervisory authority and affected customers or individuals in line with the GDPR's requirements (in general, without undue delay and, where feasible, within 72 hours of becoming aware).

Your role in security

Security is a shared responsibility. Please protect your account credentials, enable available security features such as MFA, only record meetings where you have obtained the consent required by law, and avoid sharing sensitive information that is not needed for the Services.

Certification status

Astrix handles personal data in a manner designed to comply with the GDPR, and our security programme is aligned with the ISO/IEC 27001 framework. We are continually investing in our data security.

Contact

To report a security concern or vulnerability, or to request our sub-processor list or transfer safeguards, contact security@astrix.ai.

Image

Try Astrix Free

Image

Try Astrix Free

Image

Try Astrix Free