AI Safety and Security

Last Modified: April 20, 2026

At Ferretly, we uphold the highest standards of responsible use of AI, security, compliance, and privacy to protect the data entrusted to us. Our governance practices are designed to minimize risk and ensure the confidentiality, integrity, and availability of our systems and customer data.

DATA AND PRIVACY

Access to all corporate and customer data is granted based on principles of least privilege and need-to-know governed by role and individual user profiles.
  • Only publicly available data is collected and analyzed.
  • No access to private accounts, private messages, or restricted content.
  • Client and candidate data is never used to train AI models. This is a hard architectural boundary, not a policy preference.
  • Model development uses publicly sourced, anonymized data only.
  • Built to support compliance with FCRA, EEOC guidance, Title VII, and applicable state and international privacy laws.

OUR AI APPROACH

Ferretly uses artificial intelligence to improve the speed, consistency, and scalability of social media screening, while maintaining strict human oversight and regulatory compliance.
  • AI supports our process. It does not replace human judgment.
  • All reportable findings are reviewed by trained analysts before delivery.
  • AI does not make hiring or adjudication decisions.
  • Final reports are structured for client-led evaluation.

OUR AI ARCHITECTURE

Ferretly is AI-platform agnostic by design. Our pipeline deploys a combination of proprietary ML/NLP classifiers, neural networks, and multiple third-party models, optimizing for accuracy, context, and performance rather than reliance on any single vendor. Our architecture continuously evolves to incorporate best-in-class solutions as the technologylandscape develops. We do not disclose specific model partnerships.

Our AI Does:
  • Identifies and categorizes publicly available online content.
  • Applies astandardized 13-flag behavioral classification framework.
  • Surfaces relevant findings for human verification.
  • Offers optional analytics, including Big Five (OCEAN) personality signals, which clients may choose to enable as one input among many in their own evaluation process.
Our AI Does Not Do:
  • Predict intent or future behavior, or make inferences used as standalone decision inputs.
  • Infer protected characteristics.
  • Generate or fabricate content about individuals.
  • Make automated employment decisions.

BIAS MITGATION AND CONSISTENCY

Bias mitigation is built into the foundation of our model, not bolted on after the fact. Ferretly maintains a continuously expanding library of millions of human-reviewed posts, creating an ongoing real-world feedback loop that actively corrects for emerging bias patterns. This collective validation approach means our bias neutralization improves continuously, keeping pace with real-world shifts in language and behavior.
  • Standardized 13-flag classification framework reduces subjective variance
  • Generate or fabricate content about individuals.

DATA PROTECTION AND AUTHENTICATION

Ferretly encrypts data at rest and in transit using AES 256-bit and TLS 1.2. Application access is based on configurable permissions. Ferretly utilizes MFA to prevent unauthorized access to the systems and application.

    Security Of Information

    Ferretly abides by all applicable state and federal laws pertaining to the security of data supplied to it or collected by it. Ferretly will use industry-standard physical, technical, and administrative security measures and safeguards to protect the confidentiality and security of “Personally Identifiable Information.” For example, Ferretly will employ mechanisms to help maintain a secure network, encrypt back-up data, and establish limits on employee access to information.

    PHYSICAL SECURITY

    Ferretly uses Microsoft Azure as its primary hosting environment, and we leverage redundant data centers residing in the United States of America to store and replicate both application and data.

    SECURITY COMPLIANCE

    Ferretly has obtained a SOC 2 Type II assessment provided by independent third-party auditors and we perform annual penetration tests. We are compliant with European Union General Data Protection Regulations (GDPR) as applied to Ferretly, and supports customers’ own compliance programs through product features, integration, and configuration options, as required by our customers. Ferretly complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/. Ferretly aligns its practices with Canadian privacy laws, specifically the Personal Information Protection and Electronic Documents Act (PIPEDA) and similar provincial legislation. Lastly, Ferretly conforms to all United States, State Social Media Privacy laws. To learn more visit https://help.ferretly.com/kb/guide/en/social-media-privacy-laws-FDvWXCfU1W/Steps/4853630.

    ONGOING GOVERNANCE

    Ferretly continuously evaluates its AI systems for accuracy, regulatory alignment, security and explainability. This section is reviewed and updated as regulations and capabilities evolve.

    CONTACT US

    If you have any questions or suggestions about our security and privacy controls, do not hesitate to contact us at