Home/Trust Center

Codility Trust Center

Codility is ISO/IEC 27001:2022 certified and audited every year under SOC 2 Type II. You choose a US or EU data cluster when you sign. We encrypt customer data with AES-256 at rest and TLS 1.2 or higher in transit. No AI or machine learning makes a hiring decision on Codility.

Last reviewed: 2026-10-06 · Owner: Codility Security team · Codility Limited, 9th Floor, 107 Cheapside, London EC2V 6DN

Certified and audited

ISO 27001 certified ISO/IEC 27001:2022
AICPA SOC SOC 2 Type II
GDPR and UK GDPR
CCPA compliant CCPA
OverviewData hostingSecurity controlsPrivacySubprocessorsAI governanceFairness & integrityAccessibilitySecurity reviewFAQ

Compliance at a glance

If you lead security, privacy or procurement for a team that hires with Codility, start here. Every section has its own link, so you can send a reviewer straight to the answer they need.

Standard or regulation Status Where to verify
ISO/IEC 27001:2022 Certified Certificate on request
SOC 2 Type II Audited annually Report under NDA at trust.codility.com
GDPR and UK GDPR Compliant Data Processing Agreement
CCPA Compliant Data Privacy Notice
Web Content Accessibility Guidelines, WCAG 2.2 AA Conformant Accessibility
NYC Local Law 144 Designed to support your compliance AI governance

The full control library, the SOC 2 report, our Consensus Assessments Initiative Questionnaire (CAIQ) and our cyber insurance certificate sit in the Codility Trust Center portal.

Is Codility compliant?

Yes. Codility holds an ISO/IEC 27001:2022 certificate for its information security management system, an independent auditor examines our controls every year under SOC 2 Type II, and we comply with the GDPR, the UK GDPR and the CCPA.

ISO/IEC 27001:2022

ISO/IEC 27001 is the international standard for running an information security management system, or ISMS. Our certificate covers the provision and maintenance of the Codility software platform. An external auditor checks the ISMS every year between full recertifications. The Statement of Applicability, which lists every control we apply, is available under NDA.

SOC 2 Type II

A SOC 2 Type II report is an independent auditor’s opinion on whether a company’s security controls worked as designed over a full audit period, usually twelve months. Codility is audited every year. You can request the latest report through the Trust Center portal once an NDA is in place.

GDPR, UK GDPR and CCPA

Codility complies with the EU General Data Protection Regulation, the UK GDPR and the California Consumer Privacy Act. You can check our commitments in the Data Processing Agreement, summarized in How does Codility handle personal data?

Where does Codility store customer data?

Codility runs on Amazon Web Services in two separate clusters, one in the US and one in the EU. You pick the cluster in your contract, and your platform data and its backups stay inside that cluster.

Cluster Production region Backup region App address
EU AWS eu-central-1, Germany AWS eu-west-1, Ireland app-eu.codility.com
US AWS us-east-1, United States AWS us-east-2, United States app.codility.com
info

If you don’t choose a cluster, your account runs in the US cluster. Tell your account team before signing if you need the EU.

Some services that support the platform, such as video calls and customer support tools, run in other locations. The subprocessor section explains where to find the location of each one for each cluster, so your privacy team can check every transfer.

lockapp-eu.codility.com
Sign in Work email Continue
ProductionAWS eu-central-1, FrankfurtBackupsAWS eu-west-1, Ireland
blockNo shared
data
lockapp.codility.com
Sign in Work email Continue
ProductionAWS us-east-1, United StatesBackupsAWS us-east-2, United States
The EU and US clusters are fully separate instances, each at its own address. Accounts, data and backups never cross between them.

International transfers

Where personal data leaves the EU or the UK, our Data Processing Agreement applies the European Commission’s Standard Contractual Clauses, Module 2, and the UK International Data Transfer Addendum.

How does Codility secure the platform?

Codility protects customer data with encryption, isolated environments, least-privilege access, an annual external penetration test and a tested incident response plan. Each area below summarizes the controls in place. The Trust Center portal carries the full description of every control.

cloud

Infrastructure and network

  • check_circleProduction, staging and development each run in their own AWS Virtual Private Cloud, and production data is not shared outside its environment.
  • check_circleInbound traffic is limited to HTTPS connections to designated endpoints.
  • check_circleAWS GuardDuty provides automated intrusion detection and alerts our team.
  • check_circleAWS network-level controls protect the platform against distributed denial-of-service attacks.
  • check_circleWe review AWS's attestation reports and assess AWS as a vendor at least once a year.
key

Encryption and key management

  • check_circleAll databases and customer datastores are encrypted at rest with AES-256.
  • check_circleEncryption keys live in AWS KMS hardware security modules validated to FIPS 140-3 Security Level 3 and rotate automatically every year.
  • check_circleData in transit is encrypted with TLS 1.2 or higher. Today the platform negotiates TLS 1.3.
  • check_circleBackups are encrypted, and only key personnel can access them.
deployed_code

Candidate code isolation

  • check_circleCandidate code runs in isolated containers.
code

Application security and development

  • check_circleA documented secure software development lifecycle governs every change, from requirements to deployment. Changes are authorized, tested, reviewed and approved before they reach production.
  • check_circleScanning tools check our source code and open-source dependencies, and we fix findings within internal deadlines set by risk.
  • check_circleAn external security firm runs a penetration test every year. The 2026 attestation letter is in the Trust Center portal.
  • check_circleEngineers complete secure development training as part of our annual security awareness program.
group

Identity and access for your team

  • check_circleSingle sign-on (SSO) through SAML 2.0, with sign-in started either from Codility or from your identity provider. SSO is available on the Custom plan, and Codility Support sets it up with you.
  • check_circleRoles and permissions inside the platform decide who can see candidates, results and settings.
  • check_circleA public REST API lets you export your data in machine-readable formats over encrypted connections.
admin_panel_settings

Identity and access for Codility staff

  • check_circleRole-based access on the principle of least privilege, with every user's access reviewed each quarter.
  • check_circlePrivileged access is time-limited.
  • check_circleMulti-factor authentication is required, and only company devices enrolled in our mobile device management system can reach Codility resources.
laptop_mac

People and devices

  • check_circleEvery new employee passes a background check before getting access to systems or data.
  • check_circleEvery employee and contractor signs a confidentiality agreement.
  • check_circleEveryone completes security awareness training when they join and every year after that.
  • check_circleCompany laptops use full-disk encryption and can be locked or wiped remotely. USB storage and printing are disabled by default.
handshake

Vendor risk

  • check_circleWe evaluate and monitor every third-party provider under a written Vendor Risk Assessment Procedure.
emergency

Incident response

  • check_circleA documented incident response plan covers detection, analysis, containment, eradication and recovery, and we test it at least once a year.
  • check_circleOur Infrastructure team and our Compliance and Security team own monitoring, alerting and coordination.
  • check_circleIf a personal data breach affects you, we notify you without undue delay and in any event within 24 hours, as set out in our Data Processing Agreement.
  • check_circleCodility is enrolled in the UK National Cyber Security Centre's Early Warning service.
backup

Business continuity and backups

  • check_circleOur business continuity and disaster recovery plan is reviewed, updated and exercised at least once a year.
  • check_circleBackups are encrypted and monitored for completion. We test restores of critical data every quarter and of important data every year.
  • check_circleBackups stay in the backup region of your cluster.
  • check_circleLive service status for the US and EU clusters is at status.codility.com.
lockapp.codility.com/login
Sign in keyContinue with SSO
or
Sign in with password
infoYour company’s sign-in is managed by your identity provider.
Once Codility Support has set up SSO with you, your team signs in through your identity provider. There is no SSO page in account settings.

How does Codility handle personal data?

Codility processes candidate and user data only to run assessments and interviews for you. You are the controller of that data and Codility is your processor, under a Data Processing Agreement that sets breach notice at 24 hours and deletion within 90 days of the end of processing.

What data Codility processes

We process a limited set of personal data: names, contact and account details, assessment and interview data, and technical data such as IP addresses. Our services are not designed to need special category data.

Roles under GDPR

For the data your candidates and hiring teams create on the platform, you are the controller and Codility is the processor. Codility is the controller only for its own recruitment, trial sign-ups and sales inquiries.

The Data Processing Agreement

Our current Data Processing Agreement, dated 13 August 2026, is public. Its key terms:

Term What the DPA says
Breach notificationWithout undue delay and in any event within 24 hours
Deletion after the contractWithin 90 days of the processing end date
Return of dataOn request made within 5 business days of the processing end date
Customer auditsOnce in any 12-month period, with reasonable notice
New subprocessorsAt least 30 days' prior written notice, with a right to object
International transfersStandard Contractual Clauses, Module 2, and the UK Addendum

How long candidate data is kept

You decide how long candidate data stays identifiable, and you can set automatic anonymization. When your contract ends, we delete your data within 90 days of the processing end date.

AssessmentsInterviewsCandidatesSettings
Company profile Users and roles Data residency Security Privacy
Candidate dataApplies to every assessment in this account.
Automatic anonymizationRemove identifying details from candidate records after a set time.
Anonymize candidate data 180 daysexpand_more after the assessment is completed
Save changes
You set when candidate data is anonymized. The value shown is an example.

Candidate rights

Candidates can ask to access, correct or erase their data. Because the hiring company is the controller, a candidate’s request usually goes to that company first, and we help the company respond. Candidates can also write to our Data Protection Officer directly.

Data protection impact assessments

Need a data protection impact assessment for Codility? We’ll help you complete it. Our privacy-by-design approach and supporting documents are in the Trust Center portal.

Data Protection Officer

Contact our Data Protection Officer at [email protected] or by post at 9th Floor, 107 Cheapside, London EC2V 6DN.

Who are Codility’s subprocessors?

Codility uses 13 subprocessors for the EU cluster and 14 for the US cluster. Our Data Processing Agreement of 13 August 2026 lists each one with the location it processes from.

description
Full subprocessor list, by cluster Data Processing Agreement, 13 August 2026 (PDF)
Open the DPA open_in_new

We give you at least 30 days’ written notice before adding a subprocessor, and you can object. To hear about changes as they happen, subscribe to updates in the Trust Center portal.

How does Codility use AI, and who makes the hiring decision?

A person makes every hiring decision on Codility. Our scoring is deterministic, which means the same code always gets the same score, and no AI or machine learning model decides who passes. Where AI does appear, you switch it on per assessment and every interaction is recorded for review.

AI posture at a glance

Question Answer
Does AI make or score the hiring decision?No. Scores come from deterministic tests on the candidate's work, and a person makes every decision.
Is AI switched on by default?You enable or disable the AI Assistant for each assessment.
Can reviewers see what AI did?Yes. Every AI interaction is captured as reviewable AI activity alongside the candidate's work.
Are candidates told when AI is active?Yes. The candidate sees when an assessment includes AI.

Customer controls

  • check_circleYou enable or disable the AI Assistant per assessment.
  • check_circleSettings lock once the first candidate is invited, so every candidate in an assessment gets the same conditions.
  • check_circleEvery interaction with the AI Assistant is captured as reviewable AI activity your reviewers can open next to the code.
AssessmentsInterviewsCandidatesSettings
Assessments / Senior Backend Engineer
Senior Backend Engineer
pythonsql
TasksCandidatesSettings
auto_awesome
AI AssistantCandidates can ask an AI assistant for help while they work. Every interaction is recorded as AI activity.
visibilityCandidates see that this assessment includes AI before they start.
lockSettings lock once the first candidate is invited.
You switch the AI Assistant on or off for each assessment.
AssessmentsInterviewsCandidatesSettings
Jordan LeeSenior Backend Engineer · Task 2 of 3
CodeAI activityTimeline
solution.py
1from collections import defaultdict 2 3def group_orders(orders): 4 by_customer = defaultdict(list) 5 for order in orders: 6 by_customer[order.customer_id].append(order) 7 return { 8 cid: sorted(items, key=lambda o: o.created_at) 9 for cid, items in by_customer.items() 10 }
3 interactions
Candidate prompt12:04
How do I group a list of objects by a key in Python?
AI response12:04
Suggested using collections.defaultdict.
Code inserted12:05
2 lines added to solution.py, lines 5–6
Reviewers open each AI interaction next to the candidate’s code.

Regulation

NYC Local Law 144

Codility is designed to support your compliance with New York City’s law on automated employment decision tools. A person makes the decision and scoring is deterministic. If you still need a bias audit, our team runs one as a professional service.

EU AI Act

Codility is built so that no AI system makes or materially shapes a hiring decision without a person in control, and every AI interaction can be reviewed.

How does Codility keep assessments fair?

Occupational psychologists design Codility’s assessments, and we monitor adverse impact at every cut score we measure.

Validated against real work

Across more than 1,700 evaluations, Codility’s code-quality ratings agreed with engineering managers’ ratings more than 90% of the time.

Fair in candidates’ eyes

91% of candidates say the content is fair.

Recognized

Codility’s proficiency scale won the IPAC Innovations in Assessment Award in July 2026.

Documented

Our Technical Manual follows the APA Standards for Educational and Psychological Testing and is available on request.

If you need to defend a hiring decision, our team can run an adverse impact analysis on your own data that follows EEOC guidance.

How does Codility protect assessment integrity?

Codility gives your reviewers integrity signals and reviewable evidence, and a person makes the call. No candidate is rejected automatically.

Integrity Risk

Integrity Risk rates each attempt as None, Low, Moderate or High from behavioral, similarity, identity device signals and network signals. Fixed rules produce the rating, and the reviewer sees which signals contributed.

AssessmentsInterviewsCandidatesSettings
Jordan LeeSenior Backend Engineer · Completed Oct 2, 2026
RejectMove forward
Integrity RiskLow
None · Low · Moderate · High
BehavioralLeft the assessment tab 2 times, 40 seconds in totalContributed SimilarityNo similar solutions foundNone IdentityIdentity verified by VeriffNone NetworkNo signalsNone Device integrityNo virtual machine or remote access detectedNone
person_checkReview the evidence and decide. Codility never rejects a candidate automatically.
The reviewer sees the rating and the signals behind it, then decides.

Identity verification

When you switch it on, our third-party provider, Veriff, verifies the candidate’s identity. A data protection impact assessment for this feature is available on request.

Video and snapshot proctoring

Proctoring is an add-on you switch on. Candidates are told before recording starts, and recordings and snapshots are deleted after a fixed period.

Task leakage

When a task leaks, we withdraw it from the library.

Is Codility accessible to candidates with disabilities?

Yes. Codility assessments conform to WCAG 2.2 level AA. Candidates can use screen readers and keyboard-only navigation, and Accessibility Mode supports zoom up to 400%.

record_voice_overScreen readers
keyboardKeyboard-only navigation
zoom_inZoom up to 400%

Candidates who need reasonable accommodations can ask the hiring company before they start. Our Guide to Accessibility and Reasonable Accommodations explains what is available. Our accessibility conformance report is available on request.

How do I run a security review of Codility?

Most reviews take four steps.

  1. 1

    Read the public material

    This page, the Data Processing Agreement, the Data Privacy Notice and the 2026 penetration test attestation letter in the Trust Center portal.

  2. 2

    Request the documents under NDA

    Enter your work email at trust.codility.com to get the SOC 2 Type II report, our CAIQ and our cyber insurance certificate.

  3. 3

    Send your questionnaire

    Email [email protected] with your own security questionnaire. Our CAIQ follows the Cloud Security Alliance’s standard question set, so start there.

  4. 4

    Subscribe to updates

    Follow the Trust Center portal for new subprocessors and document changes.

Frequently asked questions

Is Codility SOC 2 Type II audited?expand_more
Yes. An independent auditor examines Codility's controls every year under SOC 2 Type II. Request the report under NDA at trust.codility.com.
Is Codility ISO 27001 certified?expand_more
Yes. Codility is certified to ISO/IEC 27001:2022 for the provision and maintenance of its software platform.
Is Codility GDPR compliant?expand_more
Yes. Codility complies with the GDPR and the UK GDPR and signs a Data Processing Agreement with every customer. Our commitments are set out in the DPA and backed by our ISO 27001 and SOC 2 controls.
Where does Codility store candidate data?expand_more
On AWS, in the cluster you choose. EU data runs in Frankfurt with backups in Ireland. US data runs in North Virginia with backups in Ohio.
Can we keep our data in the EU?expand_more
Yes. Choose the EU cluster in your contract. Your platform data and backups stay in AWS Frankfurt and AWS Ireland. A few subprocessors process from other locations, listed in our Data Processing Agreement.
Which cluster is used if we don't choose one?expand_more
The US cluster. Tell your account team before signing if you need the EU.
Does Codility sign a Data Processing Agreement?expand_more
Yes. Our Data Processing Agreement of 13 August 2026 is public, and it applies to every customer.
Who are Codility's subprocessors?expand_more
Codility uses 13 subprocessors for the EU cluster and 14 for the US cluster. The full list with locations is in our Data Processing Agreement.
How are we told about a new subprocessor?expand_more
In writing, at least 30 days before the change, with the right to object. You can also subscribe to updates in the Trust Center portal.
How long does Codility keep candidate data?expand_more
As long as you choose. You can set automatic anonymization, and after your contract ends we delete your data within 90 days of the processing end date.
Does Codility use AI to score candidates or make hiring decisions?expand_more
No. Scoring is deterministic and a person makes every hiring decision. Where AI is used, you switch it on per assessment and every interaction is recorded for review.
Is Codility an automated employment decision tool under NYC Local Law 144?expand_more
Codility is designed to support your compliance with NYC Local Law 144, because a person makes the decision and scoring is deterministic. If you still need a bias audit, we offer one as a professional service.
Does Codility publish adverse impact data?expand_more
Yes, on request. We monitor adverse impact at every measured cut score, and our Technical Manual documents the method.
How does Codility protect integrity without rejecting candidates automatically?expand_more
Integrity Risk gives reviewers rated signals and the evidence behind them. A person reviews the evidence and decides. Codility never rejects a candidate automatically.
Is candidate code isolated from Codility's infrastructure?expand_more
Yes. Candidate code runs in isolated containers.
How is customer data encrypted?expand_more
With AES-256 at rest, using keys in FIPS 140-3 Level 3 hardware security modules that rotate every year, and with TLS 1.2 or higher in transit.
Does Codility support SSO?expand_more
Yes. Codility supports SAML 2.0 single sign-on, started from Codility or from your identity provider, on the Custom plan.
Is Codility accessible to candidates with disabilities?expand_more
Yes. Codility conforms to WCAG 2.2 AA, supports screen readers and keyboard navigation, and offers zoom up to 400%.
How do we get the SOC 2 report or penetration test results?expand_more
Request access at trust.codility.com with your work email. The SOC 2 report is shared under NDA. The 2026 penetration test attestation letter is in the portal.
How fast does Codility notify customers of a breach?expand_more
Without undue delay and in any event within 24 hours, as set out in our Data Processing Agreement.
How do I report a security vulnerability?expand_more
Email [email protected] with the details.

Contact

shield_lock
Security questions and vulnerability reports[email protected]
badge
Privacy and data subject requests[email protected]9th Floor, 107 Cheapside, London EC2V 6DN
folder_managed
Documents under NDA and update subscriptiontrust.codility.com
monitor_heart
Live service statusstatus.codility.com