Codility Trust Center
Codility is ISO/IEC 27001:2022 certified and audited every year under SOC 2 Type II. You choose a US or EU data cluster when you sign. We encrypt customer data with AES-256 at rest and TLS 1.2 or higher in transit. No AI or machine learning makes a hiring decision on Codility.
Last reviewed: 2026-10-06 · Owner: Codility Security team · Codility Limited, 9th Floor, 107 Cheapside, London EC2V 6DN
Certified and audited
CCPA
Compliance at a glance
If you lead security, privacy or procurement for a team that hires with Codility, start here. Every section has its own link, so you can send a reviewer straight to the answer they need.
The full control library, the SOC 2 report, our Consensus Assessments Initiative Questionnaire (CAIQ) and our cyber insurance certificate sit in the Codility Trust Center portal.
Is Codility compliant?
Yes. Codility holds an ISO/IEC 27001:2022 certificate for its information security management system, an independent auditor examines our controls every year under SOC 2 Type II, and we comply with the GDPR, the UK GDPR and the CCPA.
ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for running an information security management system, or ISMS. Our certificate covers the provision and maintenance of the Codility software platform. An external auditor checks the ISMS every year between full recertifications. The Statement of Applicability, which lists every control we apply, is available under NDA.
SOC 2 Type II
A SOC 2 Type II report is an independent auditor’s opinion on whether a company’s security controls worked as designed over a full audit period, usually twelve months. Codility is audited every year. You can request the latest report through the Trust Center portal once an NDA is in place.
GDPR, UK GDPR and CCPA
Codility complies with the EU General Data Protection Regulation, the UK GDPR and the California Consumer Privacy Act. You can check our commitments in the Data Processing Agreement, summarized in How does Codility handle personal data?
Where does Codility store customer data?
Codility runs on Amazon Web Services in two separate clusters, one in the US and one in the EU. You pick the cluster in your contract, and your platform data and its backups stay inside that cluster.
If you don’t choose a cluster, your account runs in the US cluster. Tell your account team before signing if you need the EU.
Some services that support the platform, such as video calls and customer support tools, run in other locations. The subprocessor section explains where to find the location of each one for each cluster, so your privacy team can check every transfer.
data
International transfers
Where personal data leaves the EU or the UK, our Data Processing Agreement applies the European Commission’s Standard Contractual Clauses, Module 2, and the UK International Data Transfer Addendum.
How does Codility secure the platform?
Codility protects customer data with encryption, isolated environments, least-privilege access, an annual external penetration test and a tested incident response plan. Each area below summarizes the controls in place. The Trust Center portal carries the full description of every control.
Infrastructure and network
- check_circleProduction, staging and development each run in their own AWS Virtual Private Cloud, and production data is not shared outside its environment.
- check_circleInbound traffic is limited to HTTPS connections to designated endpoints.
- check_circleAWS GuardDuty provides automated intrusion detection and alerts our team.
- check_circleAWS network-level controls protect the platform against distributed denial-of-service attacks.
- check_circleWe review AWS's attestation reports and assess AWS as a vendor at least once a year.
Encryption and key management
- check_circleAll databases and customer datastores are encrypted at rest with AES-256.
- check_circleEncryption keys live in AWS KMS hardware security modules validated to FIPS 140-3 Security Level 3 and rotate automatically every year.
- check_circleData in transit is encrypted with TLS 1.2 or higher. Today the platform negotiates TLS 1.3.
- check_circleBackups are encrypted, and only key personnel can access them.
Candidate code isolation
- check_circleCandidate code runs in isolated containers.
Application security and development
- check_circleA documented secure software development lifecycle governs every change, from requirements to deployment. Changes are authorized, tested, reviewed and approved before they reach production.
- check_circleScanning tools check our source code and open-source dependencies, and we fix findings within internal deadlines set by risk.
- check_circleAn external security firm runs a penetration test every year. The 2026 attestation letter is in the Trust Center portal.
- check_circleEngineers complete secure development training as part of our annual security awareness program.
Identity and access for your team
- check_circleSingle sign-on (SSO) through SAML 2.0, with sign-in started either from Codility or from your identity provider. SSO is available on the Custom plan, and Codility Support sets it up with you.
- check_circleRoles and permissions inside the platform decide who can see candidates, results and settings.
- check_circleA public REST API lets you export your data in machine-readable formats over encrypted connections.
Identity and access for Codility staff
- check_circleRole-based access on the principle of least privilege, with every user's access reviewed each quarter.
- check_circlePrivileged access is time-limited.
- check_circleMulti-factor authentication is required, and only company devices enrolled in our mobile device management system can reach Codility resources.
People and devices
- check_circleEvery new employee passes a background check before getting access to systems or data.
- check_circleEvery employee and contractor signs a confidentiality agreement.
- check_circleEveryone completes security awareness training when they join and every year after that.
- check_circleCompany laptops use full-disk encryption and can be locked or wiped remotely. USB storage and printing are disabled by default.
Vendor risk
- check_circleWe evaluate and monitor every third-party provider under a written Vendor Risk Assessment Procedure.
Incident response
- check_circleA documented incident response plan covers detection, analysis, containment, eradication and recovery, and we test it at least once a year.
- check_circleOur Infrastructure team and our Compliance and Security team own monitoring, alerting and coordination.
- check_circleIf a personal data breach affects you, we notify you without undue delay and in any event within 24 hours, as set out in our Data Processing Agreement.
- check_circleCodility is enrolled in the UK National Cyber Security Centre's Early Warning service.
Business continuity and backups
- check_circleOur business continuity and disaster recovery plan is reviewed, updated and exercised at least once a year.
- check_circleBackups are encrypted and monitored for completion. We test restores of critical data every quarter and of important data every year.
- check_circleBackups stay in the backup region of your cluster.
- check_circleLive service status for the US and EU clusters is at status.codility.com.
How does Codility handle personal data?
Codility processes candidate and user data only to run assessments and interviews for you. You are the controller of that data and Codility is your processor, under a Data Processing Agreement that sets breach notice at 24 hours and deletion within 90 days of the end of processing.
What data Codility processes
We process a limited set of personal data: names, contact and account details, assessment and interview data, and technical data such as IP addresses. Our services are not designed to need special category data.
Roles under GDPR
For the data your candidates and hiring teams create on the platform, you are the controller and Codility is the processor. Codility is the controller only for its own recruitment, trial sign-ups and sales inquiries.
The Data Processing Agreement
Our current Data Processing Agreement, dated 13 August 2026, is public. Its key terms:
How long candidate data is kept
You decide how long candidate data stays identifiable, and you can set automatic anonymization. When your contract ends, we delete your data within 90 days of the processing end date.
Candidate rights
Candidates can ask to access, correct or erase their data. Because the hiring company is the controller, a candidate’s request usually goes to that company first, and we help the company respond. Candidates can also write to our Data Protection Officer directly.
Data protection impact assessments
Need a data protection impact assessment for Codility? We’ll help you complete it. Our privacy-by-design approach and supporting documents are in the Trust Center portal.
Data Protection Officer
Contact our Data Protection Officer at [email protected] or by post at 9th Floor, 107 Cheapside, London EC2V 6DN.
Who are Codility’s subprocessors?
Codility uses 13 subprocessors for the EU cluster and 14 for the US cluster. Our Data Processing Agreement of 13 August 2026 lists each one with the location it processes from.
We give you at least 30 days’ written notice before adding a subprocessor, and you can object. To hear about changes as they happen, subscribe to updates in the Trust Center portal.
How does Codility use AI, and who makes the hiring decision?
A person makes every hiring decision on Codility. Our scoring is deterministic, which means the same code always gets the same score, and no AI or machine learning model decides who passes. Where AI does appear, you switch it on per assessment and every interaction is recorded for review.
AI posture at a glance
Customer controls
- check_circleYou enable or disable the AI Assistant per assessment.
- check_circleSettings lock once the first candidate is invited, so every candidate in an assessment gets the same conditions.
- check_circleEvery interaction with the AI Assistant is captured as reviewable AI activity your reviewers can open next to the code.
Regulation
NYC Local Law 144
Codility is designed to support your compliance with New York City’s law on automated employment decision tools. A person makes the decision and scoring is deterministic. If you still need a bias audit, our team runs one as a professional service.
EU AI Act
Codility is built so that no AI system makes or materially shapes a hiring decision without a person in control, and every AI interaction can be reviewed.
How does Codility keep assessments fair?
Occupational psychologists design Codility’s assessments, and we monitor adverse impact at every cut score we measure.
Validated against real work
Across more than 1,700 evaluations, Codility’s code-quality ratings agreed with engineering managers’ ratings more than 90% of the time.
Fair in candidates’ eyes
91% of candidates say the content is fair.
Recognized
Codility’s proficiency scale won the IPAC Innovations in Assessment Award in July 2026.
Documented
Our Technical Manual follows the APA Standards for Educational and Psychological Testing and is available on request.
If you need to defend a hiring decision, our team can run an adverse impact analysis on your own data that follows EEOC guidance.
How does Codility protect assessment integrity?
Codility gives your reviewers integrity signals and reviewable evidence, and a person makes the call. No candidate is rejected automatically.
Integrity Risk
Integrity Risk rates each attempt as None, Low, Moderate or High from behavioral, similarity, identity device signals and network signals. Fixed rules produce the rating, and the reviewer sees which signals contributed.
Identity verification
When you switch it on, our third-party provider, Veriff, verifies the candidate’s identity. A data protection impact assessment for this feature is available on request.
Video and snapshot proctoring
Proctoring is an add-on you switch on. Candidates are told before recording starts, and recordings and snapshots are deleted after a fixed period.
Task leakage
When a task leaks, we withdraw it from the library.
Is Codility accessible to candidates with disabilities?
Yes. Codility assessments conform to WCAG 2.2 level AA. Candidates can use screen readers and keyboard-only navigation, and Accessibility Mode supports zoom up to 400%.
Candidates who need reasonable accommodations can ask the hiring company before they start. Our Guide to Accessibility and Reasonable Accommodations explains what is available. Our accessibility conformance report is available on request.
How do I run a security review of Codility?
Most reviews take four steps.
-
1
Read the public material
This page, the Data Processing Agreement, the Data Privacy Notice and the 2026 penetration test attestation letter in the Trust Center portal.
-
2
Request the documents under NDA
Enter your work email at trust.codility.com to get the SOC 2 Type II report, our CAIQ and our cyber insurance certificate.
-
3
Send your questionnaire
Email [email protected] with your own security questionnaire. Our CAIQ follows the Cloud Security Alliance’s standard question set, so start there.
-
4
Subscribe to updates
Follow the Trust Center portal for new subprocessors and document changes.