Account and security
Signing in
Email and password, with an optional second factor.
Two-factor authentication is set up from your Profile: scan the QR code with any authenticator app and confirm a code. You are shown recovery codes once — save them somewhere that is not the phone holding the authenticator, because that phone is exactly what they exist to recover from.
Turning 2FA on applies to your own account. It is worth insisting on for anyone with the Organization Admin role.
Forgotten passwords
The reset link on the login page emails a link valid for a short window. Organization Admins can also trigger a reset for a colleague from Users, which emails that person a link — it does not reveal or set a password for them.
Single sign-on
On Advanced and above you can connect your identity provider over OIDC or SAML 2.0, and users sign in through it instead of with a password.
On Professional and above you can additionally connect SCIM 2.0, so accounts are created, updated and deactivated from your identity provider rather than by hand. Deactivating someone there revokes their sessions here.
Both are configured under Settings. Two things worth knowing before you enable SSO:
- If your company already has people signed in with passwords, set the allowed email domains for the connection. Without it, those existing accounts are refused when the identity provider tries to link to them — a deliberate guard against someone else's directory claiming your users by asserting their email address.
- SSO login keeps working if you later downgrade. We do not disable a login path and strand your users; only the ability to change the configuration is gated.
Candidate data and retention
Under Settings → Candidate data:
Retention. Candidate personal data is automatically removed a set number of days after an assessment ends — 180 by default, adjustable between 30 and 730. The assessment result survives; what goes is everything identifying the person: name, email, the details you collected, IP address, device information, and any proctoring logs, screenshots or location data.
This means your reporting and score history stay intact while the records stop being personal data. Shortening the window applies to existing data too, so a reduction can erase records the same day.
Subject requests. Two actions on a single candidate, by email address:
- Export their data — everything you hold about that person, for a GDPR Article 15 access request
- Delete their data — irreversible erasure across attempts, invitations and interviews, for an Article 17 request
Both are restricted to Organization Admins and both are audit-logged. Deletion is genuinely irreversible; there is no undo and we cannot restore it for you.
Both are scoped to your company. If another customer assessed the same person, their records are untouched and invisible to you.
What we hold, and where
Customer data is hosted in the EU and is not replicated outside it. Candidate code is executed in isolated containers with no network access, which are destroyed after the run; the submitted code itself is kept with the attempt and expires with it under your retention window.
Full detail, including the security posture and subprocessors, is on the Trust Center.
Closing an account
Cancelling a subscription stops billing but keeps the account and its data. To have the organization and everything in it erased, open a support ticket. The deletion is scheduled 30 days out, so an accidental request can be reversed within that window. After it runs, it is permanent.