Trust · Security · Compliance

The controls behind Evaluated talent. No borders.

Nuvett evaluates and ranks job candidates against each employer’s own criteria — screening thousands of applications at scale so employers decide from a shortlist, not a pile. Nuvett informs the decision; the employer makes it. This is the single view of how we protect candidate and employer data, secure our systems, and hold our AI accountable.

Corporate Registration

Registered (CAC)

Data-Protection Registration

NDPA · Underway

AI Fairness Audit

Active

ISO/IEC 27001

On Roadmap

SOC 2 Type II

On Roadmap

Data Encryption

In Transit & at Rest
01

Data Protection & Privacy

NDPA Registration Underway

Nuvett is built to comply with the Nigeria Data Protection Act (NDPA) 2023 and its General Application and Implementation Directive (GAID). We process candidate and employer data under stated lawful bases, minimise what we collect, and give data subjects clear rights over their information.

Controller & Processor Roles

  • Nuvett is the data controller for identity verification, liveness checks, the selfie-to-ID face match, the cross-tenant biometric registry, duplicate detection and duplicate-registration blocking, remote proctoring, and assessment and interview scoring. Nuvett alone determines the purposes, means, thresholds, and retention for these activities — employers can neither see nor configure them.
  • Nuvett is a data processor only for employer-supplied role and vacancy data, which we process on the employer’s behalf.

How We Verify Identity — Two Distinct Stages

  • Registration (in-house): selfie, liveness check, government-ID capture, and a face match between the selfie and the ID photograph — run entirely on Nuvett infrastructure, with facial analysis in the candidate’s own browser. No third party is involved and the document is not checked against government records. It establishes that the person present matches the document presented.
  • Hire stage (Smile Identity): when an employer invites a candidate on a role requiring identity verification, the candidate may complete an employer-funded check through Smile Identity — a live selfie plus government ID, validated against government records (the only government-verified step). The candidate initiates it and may decline; declining leaves the profile unverified for the employer to weigh. Nuvett retains the provider selfie for an in-house cross-match against the registration selfie.

Biometric Registry & Duplicate Prevention

  • Facial templates are enrolled in the duplicate-detection registry only on the candidate’s separate, explicit consent, and a 1:N similarity search runs across all candidate accounts platform-wide.
  • Registry entries are retained for a fixed period (currently 179 days), then deleted automatically; results are visible to Nuvett administrators only and never to employers.
  • Duplicate registrations are blocked on same email, same ID number, or same face combined with same date of birth; a facial match alone only flags for review and never blocks or rejects anyone.

Retention — by Data Type

  • Biometric registry templates: a fixed period (currently 179 days) from enrolment, regardless of any hiring outcome.
  • Verification selfies, ID document images, interview and presentation recordings, and profile/assessment data: kept while the account exists, and erased when the candidate deletes their account (a minimal redacted deletion record is retained to honour the erasure).
  • Anything held longer only where a legal obligation requires it.

Rights & Governance

  • A designated Data Protection Officer oversees privacy practices and handles data-subject requests (dpo@getnuvett.com).
  • Candidates can access, correct, or delete their personal data, request human review of any automated score, and withdraw consent at any time.
  • Every data subject has the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
Read the Privacy Policy →
02

Information Security

Active Controls

We protect data with layered technical and organisational controls, and we are building toward independent certification of our security management system.

Technical Controls

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control with least-privilege access to production.
  • Secrets and credentials in managed, access-controlled stores, never in application code.
  • Continuous monitoring and logging of system activity.

Operational Controls

  • A documented incident and breach-response process, with notification obligations under the NDPA.
  • Regular dependency and vulnerability review.
  • Separation of duties between development, deployment, and administration.

Certifications & Roadmap

ISO/IEC 27001On Roadmap

Groundwork (risk assessment, control implementation, security policies) in progress.

SOC 2 Type IIOn Roadmap

Scope and readiness assessment being defined.

03

Responsible & Fair AI

Fairness Audit Active

Hiring AI carries real discrimination risk. Nuvett tests its assessment engine for adverse impact, keeps humans in the decision loop, and publishes its methodology rather than asking you to take fairness on trust.

What We Test for

  • Adverse-impact analysis using selection-rate comparisons (four-fifths / 80% rule) across candidate groups.
  • Assessment design informed by the EU AI Act’s high-risk framework and US Title VII adverse-impact principles.
  • Review of outcomes against protected characteristics recognised under applicable law.

Safeguards

  • Human oversight — employers make the final hiring decision; Nuvett informs, it does not decide autonomously.
  • Explainability of assessment outputs so decisions can be reviewed.
  • A defined process for what happens when disparity is detected, including review and remediation.
Read the Responsible AI policy →

How the Fairness Test Works

Metric
Adverse Impact Ratio (a group’s selection rate ÷ the highest group’s rate); flag any result below 0.80, the four-fifths rule.
Groups Tested
For Nigerian employers, the grounds under s.42 of the Constitution (ethnic group, place of origin, sex, religion, political opinion) plus disability and age; for US employers, race, sex, and age 40+.
Reliability
We don’t score the test on groups below ~30 candidates, and add a statistical-significance check (p < 0.05) once volume allows.
Proxy Check
We review that scoring criteria don’t stand in for a protected trait (e.g. school, address, name).
Cadence & Response
Run per role at close and aggregated quarterly; a ratio below 0.80 or a significant disparity triggers review, re-weighting, or flagging of the role.
Read the full AI Fairness & Bias Testing Methodology →
04

Data Residency & Sub-Processors

We use a small, vetted set of infrastructure and service providers, each bound by data-processing terms consistent with our own obligations to you. The current list is published here — candidates and employers do not need a Data Processing Agreement to see who processes their data.

Sub-ProcessorFunctionData ReceivedCountry
Smile IdentityHire-stage identity verification against government records (employer-funded, candidate-initiated)Live selfie (SmartSelfie), government ID details, and identity attributesUnited States (HQ); processing locations per Smile Identity’s privacy notice
SupabaseCloud database and encrypted file storage (application data, recordings, ID images in private buckets)Platform data, including candidate profiles, assessment data, and stored mediaUnited States (managed cloud)
VercelApplication hosting and content deliveryPlatform traffic and application data in transitUnited States (global edge)
Fly.ioVoice-integrity service — extracts an audio rendition of the recording for transcription; voice-activity detection and speaker diarization for assessment integrityFull interview and case-study recording (video and audio)France
OpenAISpeech-to-text transcription of interview/presentation recordings; interview question audio (text-to-speech)Audio-only rendition of interview and presentation recordings, and question textUnited States
AnthropicAI scoring and summarisation of assessment and interview responsesAssessment responses, transcripts, and role criteria (no biometric data)United States
ResendTransactional email deliveryName, email address, and notification contentUnited States
Monnify (Moniepoint)Employer payments and wallet fundingEmployer billing details and payment transactions (no candidate data)Nigeria

A recording’s full journey: the interview or case-study recording uploads from the candidate’s browser directly to private storage (Supabase); the voice-integrity service on Fly.io (France) then receives it to extract a compressed audio-only rendition for transcription and to run voice-activity and speaker-count integrity checks; OpenAI receives only that audio rendition for transcription (the rendition is deleted immediately after); Anthropic receives the text transcript for scoring; and the employer views the stored video through the platform. Facial analysis at registration and proctoring analysis run in the candidate’s own browser — no sub-processor receives facial templates or the biometric registry, and no sub-processor other than Fly.io receives the video. Where a sub-processor processes personal data outside Nigeria in a jurisdiction without an NDPC adequacy decision, the transfer rests on the data subject’s consent and contractual safeguards.

05

Corporate & Legal

Registered Entity

Nuvett operates through a defined corporate structure with a registered Nigerian operating entity, so contracts, invoicing, and liability sit with a real, accountable company.

Entity & Registration

  • US parent company holding the platform and intellectual property.
  • Nigerian operating entity, registered with the Corporate Affairs Commission (CAC), for local contracts and billing.
  • NDPA data-controller/processor registration underway.

Offices

United States (parent)

3104 East Camelback Road, Phoenix, Arizona 85016, USA

+1 (480) 919-9298

Nigeria (operating entity)

Mulliner Towers, 39 Alfred Rewane Road, Ikoyi, Lagos 101233, Nigeria

Governing Documents

  • Terms of Service — commercial and usage terms.
  • Service Level Agreement — availability and support commitments.
  • Data Processing Agreement — available to enterprise customers before any candidate data is shared.

Get in Touch

Documentation & Security Requests

Procurement and vendor-risk teams can request our DPA and security documentation directly (the sub-processor list is published above). We respond to security and data-protection enquiries promptly.

Last updated: 30 July 2026 · Complaints may be lodged with the Nigeria Data Protection Commission (NDPC) at any time