Skip to content

Security and data

Understand how
your work is handled.

A practical overview of access, saved records and optional AI processing. Use it to identify the questions to resolve before your team starts an evaluation.

Sign-in and access

Provider-based sign-in
Use the sign-in options available on the login page. Company identity-provider setup should be agreed with your administrator before rollout.
Organization and workspace roles
Organization administrators manage their team. Workspace managers and editors have different editing permissions. Workspaces within one organization are not separate confidential client accounts.
Account deactivation
When SCIM is configured, access is revoked after the service receives and processes the deactivation. Signing out at an identity provider alone does not necessarily end an existing app session.
Session controls
Server-side sessions expire after 30 days. The service includes sign-in rate limits, request-size limits and checks on authenticated requests.

Your data

Organization boundaries
Access to organization data is checked by the application. Public record links are a separate sharing choice: review what is included before enabling sharing.
Export and account removal
Account export includes profile information and authored assessments. It is not a complete organization backup. Removing an account retains shared organization work with pseudonymized authorship; managed accounts may require an administrator.
Hosting and processing
Confirm hosting location, backup retention, active service providers and any required data-processing agreement before uploading confidential material. These details depend on the hosted service arrangement.

Records and review

Saved snapshots
Saved records retain the scoring inputs captured at the time. Approved records are locked against normal editing in the app. This is not a promise of indefinite retention or an independently certified signature.
Change history
Model changes and decision actions produce audit entries. Published model versions can be reviewed and restored using the app’s controls.
Review remains a team responsibility
A recorded approval shows who approved the record. It does not independently verify vendor claims or guarantee the outcome of the decision.

AI assistance

Optional score suggestions and explanations
When enabled, AI can draft criterion scores from supplied evidence or explain a result. These actions can send decision content and evidence documents to the configured provider. Review suggestions before applying them.
Calculated rankings
The ranking is calculated by the scoring engine. AI-suggested inputs can affect it if you apply them, so their accuracy still matters.
Provider terms
CriteriaKit does not train models on your content. The configured AI provider’s retention and training terms govern requests sent to it. Confirm the provider and account terms before using AI with confidential information.

Assurance status

Independent assurance
CriteriaKit is not SOC 2 certified. A control mapping is not an independent audit. Contact us to discuss the evidence your organization requires before adopting the service.
Deployment review
Review identity setup, sharing permissions, service recovery and contractual requirements with us before a wider rollout.

Discuss your requirements.