Security & Privacy

Your data stays yours.
We only process what we need.

ARBON was built with privacy by design. Audio is never stored, what persists is processed and encrypted, and you can delete any data whenever you want without being held hostage by the platform.

Audio is never stored

Call audio is processed in real time, as a stream, by the transcription provider ARBON contracts with, and is permanently and irreversibly discarded immediately after the text is generated. Audio is never recorded, retained, copied, or saved to disk — not on ARBON's servers, nor on the transcription provider's. The only artifact that persists is the transcribed text of the conversation.

No raw recording of the interview exists, anywhere

No layer of the Platform holds a replayable recording of the interview. What persists after processing is exclusively the encrypted transcript and the analytical artifacts derived from it — behavioral score, alerts, and textual evidence. It is not possible, even internally, to reconstruct or replay the original audio or video of the conversation from what is stored on the Platform.

Data is processed, never exposed

All processing takes place on controlled infrastructure, with encryption in transit and at rest and access control via session token combined with mandatory two-factor authentication (2FA) at sign-in — there is no way to skip this step. No one outside the contractual relationship has access to raw data, and the AI model providers ARBON contracts with do not use client-submitted data to train, fine-tune, or improve their own models, under the commercial terms signed with those providers.

Sensitive data is filtered before the report

ARBON's analysis pipeline is designed to identify and filter out sensitive personal information spontaneously mentioned during an interview (such as health, religion, sexual orientation, political opinion, or union membership) before the Report is generated. When detected, that information is not used as an analysis factor and is not reproduced in the final Report delivered to the company. This does not replace the client company's obligation to obtain the candidate's proper consent for the interview as a whole, under the Privacy Policy.

Internal use is anonymized and aggregated

When Platform usage data is used to calibrate, evaluate, and improve our analysis workflows, this happens exclusively in anonymized and aggregated form, with no possibility of re-identifying the candidate or the client company. Sensitive personal data is never used for this purpose — never identifiable raw data — and the client company may revoke this authorization at any time, in writing.

Right to erasure

Deleting an analysis deletes the transcript, score, alerts, and any derived data. Deleting the account deletes the entire organization in cascade. No secret backups left behind, subject only to the retention periods set out in the Privacy Policy and any applicable legal retention obligations.

Auditable infrastructure with data residency

The primary database runs on a server located in Brazil. Auditable access logs — who saw what, and when — are available to Scale-plan customers on request. For companies with specific data-residency or isolation requirements, we offer a dedicated (single-tenant) environment in a specific region, under commercial negotiation.

LGPD/GDPR compliance

We collect only the data needed to deliver the service. The candidate, as the data subject, has the right to request access, correction, portability, deletion, and review of decisions made solely on the basis of automated processing, under arts. 9, 18, and 20 of Law No. 13.709/2018 (LGPD) — rights exercised with the client company, the controller of that data. For Scale customers, we provide a Data Processing Agreement (DPA) compatible with the LGPD and the GDPR.

Encryption in transit and at rest

All connections to the Platform travel over TLS. Data stored in the database is protected with AES-256 encryption. Passwords are never kept in plain text — they are protected with bcrypt hashing. Authentication uses digitally signed, short-lived tokens that are rotated periodically.

Compliance and contracts

For Scale customers we offer:

  • Data Processing Agreement (DPA) compatible with GDPR/LGPD
  • Custom clauses (NDA, specific retention, etc.)
  • Exportable audit logs (who saw what, and when)
  • 99.9% SLA with automatic credits if breached
  • Single-tenant or a specific data region (under negotiation)
Talk to sales about compliance

Report a vulnerability

Found a security issue? Email arbon@arbonhr.com with details and a PoC. We take it seriously, respond within 48h and give public credit to anyone who wants it. We do not retaliate against good-faith research.

See also: Privacy Policy · Terms of Use