Security and data
Understand how
your work is handled.
A practical overview of access, saved records and optional AI processing. Use it to identify the questions to resolve before your team starts an evaluation.
Sign-in and access
- Provider-based sign-in
- Use the sign-in options available on the login page. Company identity-provider setup should be agreed with your administrator before rollout.
- Organization and workspace roles
- Organization administrators manage their team. Workspace managers and editors have different editing permissions. Workspaces within one organization are not separate confidential client accounts.
- Account deactivation
- When SCIM is configured, access is revoked after the service receives and processes the deactivation. Signing out at an identity provider alone does not necessarily end an existing app session.
- Session controls
- Server-side sessions expire after 30 days. The service includes sign-in rate limits, request-size limits and checks on authenticated requests.
Your data
- Organization boundaries
- Access to organization data is checked by the application. Public record links are a separate sharing choice: review what is included before enabling sharing.
- Export and account removal
- Account export includes profile information and authored assessments. It is not a complete organization backup. Removing an account retains shared organization work with pseudonymized authorship; managed accounts may require an administrator.
- Hosting and processing
- Confirm hosting location, backup retention, active service providers and any required data-processing agreement before uploading confidential material. These details depend on the hosted service arrangement.
Records and review
- Saved snapshots
- Saved records retain the scoring inputs captured at the time. Approved records are locked against normal editing in the app. This is not a promise of indefinite retention or an independently certified signature.
- Change history
- Model changes and decision actions produce audit entries. Published model versions can be reviewed and restored using the app’s controls.
- Review remains a team responsibility
- A recorded approval shows who approved the record. It does not independently verify vendor claims or guarantee the outcome of the decision.
AI assistance
- Optional score suggestions and explanations
- When enabled, AI can draft criterion scores from supplied evidence or explain a result. These actions can send decision content and evidence documents to the configured provider. Review suggestions before applying them.
- Calculated rankings
- The ranking is calculated by the scoring engine. AI-suggested inputs can affect it if you apply them, so their accuracy still matters.
- Provider terms
- CriteriaKit does not train models on your content. The configured AI provider’s retention and training terms govern requests sent to it. Confirm the provider and account terms before using AI with confidential information.
Assurance status
- Independent assurance
- CriteriaKit is not SOC 2 certified. A control mapping is not an independent audit. Contact us to discuss the evidence your organization requires before adopting the service.
- Deployment review
- Review identity setup, sharing permissions, service recovery and contractual requirements with us before a wider rollout.