Trust · Security · Compliance

The controls behind Evaluated talent. No borders.

Nuvett evaluates and ranks job candidates against each employer’s own criteria — screening thousands of applications at scale so employers decide from a shortlist, not a pile. Nuvett informs the decision; the employer makes it. This is the single view of how we protect candidate and employer data, secure our systems, and hold our AI accountable.

Corporate Registration

Registered (CAC)

Data-Protection Registration

NDPA · Underway

AI Fairness Audit

Active

ISO/IEC 27001

On Roadmap

SOC 2 Type II

On Roadmap

Data Encryption

In Transit & at Rest
01

Data Protection & Privacy

NDPA Registration Underway

Nuvett is built to comply with the Nigeria Data Protection Act (NDPA) 2023. We process candidate and employer data under a defined lawful basis, minimise what we collect, and give data subjects clear rights over their information.

How We Handle Candidate Data

  • Collected with consent + a stated lawful basis, used only for the assessment/verification the employer requested.
  • Biometric & identity data treated as sensitive personal data, processed through a dedicated identity-verification partner.
  • Retained only as long as needed for the hiring decision and legal record, then deleted or anonymised.

Rights & Governance

  • A designated Data Protection Officer oversees privacy practices and handles data-subject requests.
  • Candidates can request access, correction, or deletion of their personal data.
  • Employers act as data controllers; Nuvett acts as processor under a Data Processing Agreement.
Read the Privacy Policy →
02

Information Security

Active Controls

We protect data with layered technical and organisational controls, and we are building toward independent certification of our security management system.

Technical Controls

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control with least-privilege access to production.
  • Secrets and credentials in managed, access-controlled stores, never in application code.
  • Continuous monitoring and logging of system activity.

Operational Controls

  • A documented incident and breach-response process, with notification obligations under the NDPA.
  • Regular dependency and vulnerability review.
  • Separation of duties between development, deployment, and administration.

Certifications & Roadmap

ISO/IEC 27001On Roadmap

Groundwork (risk assessment, control implementation, security policies) in progress.

SOC 2 Type IIOn Roadmap

Scope and readiness assessment being defined.

03

Responsible & Fair AI

Fairness Audit Active

Hiring AI carries real discrimination risk. Nuvett tests its assessment engine for adverse impact, keeps humans in the decision loop, and publishes its methodology rather than asking you to take fairness on trust.

What We Test for

  • Adverse-impact analysis using selection-rate comparisons (four-fifths / 80% rule) across candidate groups.
  • Assessment design informed by the EU AI Act’s high-risk framework and US Title VII adverse-impact principles.
  • Review of outcomes against protected characteristics recognised under applicable law.

Safeguards

  • Human oversight — employers make the final hiring decision; Nuvett informs, it does not decide autonomously.
  • Explainability of assessment outputs so decisions can be reviewed.
  • A defined process for what happens when disparity is detected, including review and remediation.
Read the Responsible AI policy →

How the Fairness Test Works

Metric
Adverse Impact Ratio (a group’s selection rate ÷ the highest group’s rate); flag any result below 0.80, the four-fifths rule.
Groups Tested
For Nigerian employers, the grounds under s.42 of the Constitution (ethnic group, place of origin, sex, religion, political opinion) plus disability and age; for US employers, race, sex, and age 40+.
Reliability
We don’t score the test on groups below ~30 candidates, and add a statistical-significance check (p < 0.05) once volume allows.
Proxy Check
We review that scoring criteria don’t stand in for a protected trait (e.g. school, address, name).
Cadence & Response
Run per role at close and aggregated quarterly; a ratio below 0.80 or a significant disparity triggers review, re-weighting, or flagging of the role.
Read the full AI Fairness & Bias Testing Methodology →
04

Data Residency & Sub-Processors

We use a small, vetted set of infrastructure and service providers, each bound by data-processing terms consistent with our own obligations to you. A current sub-processor list and full data-flow detail are provided under our Data Processing Agreement on request.

05

Corporate & Legal

Registered Entity

Nuvett operates through a defined corporate structure with a registered Nigerian operating entity, so contracts, invoicing, and liability sit with a real, accountable company.

Entity & Registration

  • US parent company holding the platform and intellectual property.
  • Nigerian operating entity, registered with the Corporate Affairs Commission (CAC), for local contracts and billing.
  • NDPA data-controller/processor registration underway.

Offices

United States (parent)

3104 East Camelback Road, Phoenix, Arizona 85016, USA

+1 (480) 919-9298

Nigeria (operating entity)

Mulliner Towers, 39 Alfred Rewane Road, Ikoyi, Lagos 101233, Nigeria

Governing Documents

  • Terms of Service — commercial and usage terms.
  • Service Level Agreement — availability and support commitments.
  • Data Processing Agreement — available to enterprise customers before any candidate data is shared.

Get in Touch

Documentation & Security Requests

Procurement and vendor-risk teams can request our DPA, sub-processor list, and security documentation directly. We respond to security and data-protection enquiries promptly.

Last updated: 11 July 2026