Security and employee trust
Employee trust is a product requirement, not a disclaimer.
Workforce diagnostics require employee participation. Participation requires trust. Tezox is designed around specific, enforceable safeguards — not general assurances. This page describes every one of them.
Review the diagnostic plan“Tezox does not make employment decisions. It does not identify individual participants from their responses. It does not introduce conversation topics the customer has not approved. Every finding is qualified with confidence and limitations. The only people who act on Tezox findings are humans who have reviewed them.”
These are not claims about intent. They are structural constraints built into how the platform works. Each of the safeguards described below is a specific, verifiable feature — not a general assurance.
Purpose and scope
Purpose-limited conversations
Each diagnostic covers only the topics the customer approves. Tezox does not run open-ended exploration or introduce conversation topics beyond the approved scope.
Customer-approved topics
Conversation topics are reviewed and signed off by the customer before any participant invitation is sent. No question reaches a participant without explicit HR approval.
No autonomous employment decisions
Tezox identifies patterns and recommends actions. It does not make hiring, firing, promotion, compensation, disciplinary, or performance-management decisions. Every consequential decision requires human review.
Participant protections
Participant notice
Every participant receives a clear explanation of the diagnostic purpose, topic scope, and how their response will be handled — before they answer the first question. Participation is voluntary.
Reporting thresholds
Individual responses are never surfaced. Findings are reported only for groups that meet the minimum participant threshold. Groups below threshold are noted but not broken out.
Evidence attribution
Findings are attributed to themes and populations, not to individuals. Representative evidence is presented as synthesized themes, not individual quotes that could identify a participant.
Employee correction
Participants may contact HR to dispute or correct information about how their participation was represented. Disputes are acknowledged within two business days and resolved within ten business days by the customer's HR team, with platform support as needed.
Data governance
Data-retention controls
Conversation data is retained only for the period specified by the customer during configuration. Customers can specify shorter retention periods for sensitive diagnostics.
Data isolation
Customer data is logically isolated at the application layer using per-tenant data partitioning. Each customer's conversation data, findings, and reports are stored in dedicated, scoped partitions. One customer cannot access another customer's data through the platform, the API, or the reporting layer.
Encryption
Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption. Encryption keys are managed through a dedicated key management service with automatic rotation.
Auditability
Actions taken within the platform — approvals, report access, data exports — are logged and auditable by the customer. Audit logs are retained for the duration of the customer contract plus 12 months and are accessible to customer administrators through the governance dashboard.
Access and permissions
Role-based access
Different users see different things. An HRBP may see full findings; a business leader may see the action plan only. Access levels are configured by the customer.
HR review at every step
HR reviews diagnostic scope, participant communications, and findings before anything reaches business leaders. The platform does not bypass the HR function.
Escalation protocols
Conversations that suggest a situation requiring human investigation are flagged for HR review — not acted on autonomously. Tezox routes concerns; it does not resolve them.
Limits on inference
No psychological or medical inference
Tezox does not attempt to infer mental health status, medical conditions, personality traits, or psychological profiles from participant responses.
Uncertainty is explicit
Every finding carries a confidence rating. Low-confidence findings are flagged as such and are not recommended as the basis for consequential decisions without additional evidence.
Limitations are required, not optional
Every report includes a dedicated limitations section. Findings without acknowledged limitations would not be honest — and they would not be useful.
Customer governance
Customer governance responsibilities
The customer is responsible for communicating the diagnostic purpose to their workforce, complying with applicable employment and privacy law, and ensuring that findings are used appropriately.
Legal counsel
For diagnostics with employee-relations implications, Tezox recommends that findings are reviewed by the customer's legal counsel before any action is taken.
Compliance
Tezox is designed to support customer compliance with GDPR, CCPA, and applicable employment-privacy regulations. The platform provides data-retention controls, participant consent mechanisms, data-export and deletion capabilities, and processing records that customers can use to meet their regulatory obligations. SOC 2 Type II certification is in progress.
Questions about security, governance, or compliance?
We will walk through the technical and governance details relevant to your organization in a 30-minute call.
Book a diagnostic discussion