Guide

AI HR Assistant Security: SOC 2, Zero-Training, and Tenant Isolation Explained

Before rolling out an AI HR assistant, HR and IT teams should verify three things in writing: SOC 2 Type II readiness (independently audited security controls), a zero data-training policy(your data never trains the vendor's models), and logical tenant isolation (your data can never be queried by another customer). Here's what each of those actually means, using Eva's own security posture as a worked example.

SOC 2 Type II: audited, not just documented

A SOC 2 Type II report confirms that a vendor's controls — access management, encryption, monitoring, incident response, vendor risk management — were tested and held up over a real audit window, not just written into a policy document. Eva's infrastructure, processes, and controls are designed to meet SOC 2 Type II requirements; Vistry maintains comprehensive security documentation and has completed an independent external security assessment, with a penetration testing engagement currently underway.

Zero data-training: your HR conversations stay yours

Ask any AI vendor directly whether your prompts and documents are used to train their models. Eva's answer is no: HR information, employee conversations, and documents are not used to improve Vistry's proprietary AI systems, and third-party AI subprocessors are contractually restricted to processing data solely to deliver the service — commitments documented in Vistry's Terms of Service.

Tenant isolation: no shared data between customers

Multi-tenant AI products need to guarantee that one customer's data can't surface in another customer's answers. Eva enforces this with row-level tenant scoping on every customer data query at the application layer, role-based access control scoped within each organization, and access logging and auditing across the board.

The rest of the checklist

  • AES-256 encryption at rest, TLS 1.2+ (TLS 1.3 by default) in transit
  • Role-based access control (RBAC) with granular permissions
  • Hosted on Google Cloud Platform with enterprise-grade security
  • Automated daily backups with point-in-time recovery
  • Comprehensive audit logs, filterable by user, action, and date range
  • Designed to support GDPR and CCPA compliance obligations

Frequently asked questions

What does SOC 2 Type II readiness actually mean for an AI HR assistant?

SOC 2 Type II means an independent auditor verifies that a vendor's security controls (access controls, encryption, monitoring, incident response, vendor risk management) actually held up over a real audit window, not just that policies are written down. Eva's infrastructure, processes, and controls are designed to meet SOC 2 Type II requirements, with comprehensive security documentation and an independent external security assessment completed; a penetration testing engagement is currently underway.

What is a zero data-training policy, and why does it matter for HR data?

A zero data-training policy means your HR conversations and documents are never used to train the vendor's AI models, so nothing an employee tells the assistant can leak into another customer's answers or a future model version. Eva's zero data-training policy applies to your HR information, employee conversations, and documents, and Vistry's third-party AI subprocessors are contractually restricted to processing data solely to deliver the service.

What is tenant isolation, and how is it enforced?

Tenant isolation means one customer's data can never be queried or surfaced by another customer's users. Eva enforces this with row-level tenant scoping on every customer data query at the application layer, role-based access control within each organization, and access logging and auditing on top of that.

How is data encrypted?

AES-256 encryption is used for data at rest, and TLS 1.2+ (TLS 1.3 by default) for all data in transit.

Where is the data hosted, and what happens if something goes wrong?

Eva is hosted on Google Cloud Platform with enterprise-grade security, backed by automated daily backups and point-in-time recovery.

Can we audit what happened in our own tenant?

Yes. Every action in Eva is logged and auditable, covering login and session tracking, document access and modifications, configuration changes, API calls and integrations, and export/reporting activity, filterable by user, action, and date range.

See Eva's full security and compliance posture.

Visit the Trust Center
prod · 68c865b · 2026-08-24T23:20:10Z

Cookie preferences

We use necessary cookies to run the site. With your consent, we also use analytics, experience diagnostics, and marketing cookies to improve the site and measure campaigns.