How Miki protects candidate and assessment data.
Vulnerability reports: security@meetmiki.com
Security
You're trusting Miki with candidate conversations, assessment data, and hiring decisions. Here's how we protect that trust.
Vulnerability reports: security@meetmiki.com
Control layers
Encryption, access controls, and disclosure practices built for teams handling sensitive candidate and assessment data.
Data protection
Access control
Integrations
Monitoring
Data privacy
Security controls matter. So does what we do with the data after it enters the product.
By default, customer workspace content is not used to train shared or public AI models.
We support cleanup and deletion workflows so candidate data does not need to sit around indefinitely.
Teams can export assessment data and request deletion of candidate records when needed.
Patent pending
When AI administers an assessment, it can also help challenge suspicious answers while the conversation is still live — not just after the fact.
Active Integrity Probing™ is designed to help flag AI-assisted responses, live coaching, copy-paste behavior, and response-pattern anomalies during the assessment itself.
It is meant to strengthen reviewer judgment, not replace it. Signals surface in context so hiring teams can investigate with a human in the loop.
Callback, pivot, paraphrase, and contradiction checks can pressure-test ownership of an answer in real time.
Timing anomalies are reviewed against the candidate’s own baseline, not a generic benchmark.
Sudden shifts in wording, specificity, or register can surface for review.
Signals are summarized into reviewer context so hiring teams can investigate instead of guessing.
Compliance
SOC 2 remains in progress. Completed controls and current commitments are listed below.
| Item | Status |
|---|---|
| SOC 2 Type II | In progress — roadmap committed |
| GDPR | Compliant data handling + deletion support |
| Data encryption at rest | AES-256-GCM |
| Data encryption in transit | TLS 1.3 |
| Access controls | Role-based permissions + team scoping |
| Responsible disclosure | security@meetmiki.com |
Report it to security@meetmiki.com. We acknowledge reports within 24 hours and coordinate remediation directly.
We're happy to walk through architecture, answer a security questionnaire, or join a call with your security team.