} })

Trust and Security

Exordiom places skilled professionals from India and the Philippines and acts as the Employer of Record for every person it places. Exordiom is the legal employer in the worker's country and carries the employment contract, payroll, statutory benefits, and local compliance. You direct the work.

Placed professionals work inside your systems, on accounts you issue, on devices you secure. Exordiom never stores, processes, or hosts your customer data. So the controls that matter are the ones around the person and the device, and that is what this page covers: how people are vetted, how IP is assigned, how access is controlled, what we carry in insurance, and what we hand your security team during review. If something you need is not here, ask and we will send it under NDA.

Who is the legal employer?

Exordiom employs each placed professional in their country of residence under an Employer of Record arrangement. We hold the local employment contract and handle payroll, statutory benefits, tax withholding, leave, and termination in that jurisdiction. You manage the person's day to day work and own the output.

We name the employing entity for each country in the engagement documents before anyone starts. We currently recruit and employ in India and the Philippines.

Certifications

SOC 2 and ISO 27001 audit the systems a vendor uses to store and process customer data. Exordiom's model keeps your data out of our systems entirely: placed professionals work inside your environment, on accounts you issue, on devices you secure, under your audit trail. There is no Exordiom system holding your data for an auditor to certify, so those certifications do not apply to how we work.

Our security posture sits in five places: who we hire, what they sign, how devices are secured, how access is granted and revoked, and what we carry in insurance. Each is documented below and available for your vendor review.

How are people vetted?

We recruit people who are currently employed at strong companies for a named client role. Exordiom does not keep a bench.

Every candidate goes through a multi-round process before you see them:

  • Identity verification against government ID, in person or on live video
  • A proprietary AI interviewing platform that screens the full applicant pool against the specific role, scoring experience, technical depth, and communication
  • Human interview rounds scoring character, acumen, grit, and experience
  • Background screening covering identity, employment history, education, and criminal record, run by an accredited third-party screening provider to one global minimum standard, adjusted only where local law limits what can be checked
  • Reference checks

The same criteria apply in every market we recruit from. You run the final interview and keep the final say.

What does the professional sign?

Before day one, every placed professional signs:

  • A confidentiality agreement covering your information, surviving the end of the engagement
  • An assignment of all work product and related IP to you, executed under the law of the worker's own country so it holds where the person sits
  • A carve-out naming the person's pre-existing tools and materials
  • Acceptable use terms for your systems and data

The same obligations run through our master agreement with you, so you hold them against both Exordiom and the individual.

Who owns the intellectual property?

You do. Work product created for you under an engagement is assigned to you in the master agreement and again in the worker's local employment agreement. A single governing-law contract does not reliably transfer inventions from a worker employed in another country, which is why we execute the assignment twice. The full clause is in our Terms of Service, and we will provide the local-law assignment language on request under NDA.

How are devices secured?

Exordiom procures the laptop to your specification. If you would rather ship your own pre-imaged device, we handle the logistics: customs, delivery to the professional, return shipping when the assignment ends, and replacement if hardware fails. Either way, you own the security layer on it: MDM enrollment, disk encryption, endpoint agents, hardware keys, and any other control your policy requires.

We built it this way on purpose. Your security team already runs one stack across every employee, and a placed professional should sit inside it, not beside it. A second vendor-run MDM creates a gap your auditors cannot see into.

Our IT team enrolls each device into your tooling before the person's first day and supports your requirements for the life of the engagement. For clients we have deployed client-managed MDM, YubiKey hardware keys, full-disk encryption, and endpoint monitoring. Tell us your standard and we will meet it.

How is access controlled?

Placed professionals work inside your systems on accounts you issue and control. You set permissions, you hold the audit trail, and you can revoke access at any moment. Exordiom never needs a copy of your production data to staff a role.

Access to source code, production environments, and product IP is granted only when you authorize it in writing and the role requires it. Personnel have no independent administrative rights or deployment authority.

Offboarding: we notify you the same day an assignment ends, you revoke access, and our IT team confirms the device has been wiped or returned within 24 hours.

Incident reporting

If we learn of a security incident involving a placed professional or a device we procured, we tell you within 24 hours of discovery and work under your incident process from there.

Insurance

Exordiom carries general liability, cyber liability, and professional liability coverage. A certificate of insurance naming your company as certificate holder is available on request.

Regulated work

Regulated buyers ask two questions: what audited certifications exist, and what the contract commits to. Across managed staffing and Employer of Record providers, no one publishes a healthcare-specific or fintech-specific compliance program, so this gets settled in the contract and in diligence.

For regulated engagements we agree in writing: which regions may access which categories of data, the background screening standard applied, IP assignment enforceable in each worker's jurisdiction, device and access requirements, and responsibility for export classification where the work touches controlled technology.

What happens after someone starts?

Exordiom runs Hypercare, a structured post-hire program on a fixed cadence:

  • Kick-off and onboarding on day one
  • Two 15-minute check-ins in week one, one with you and one with the hire
  • One 15-minute and one 30-minute joint sync in week two
  • Every four weeks from week six onward

It is front-loaded because ramp problems, unclear expectations, and scope drift are cheapest to fix in the first two weeks. The program is staffed by former operators and customer success leads from high-growth software companies.

There is no minimum term. A placed professional who leaves or does not work out is replaced under a 10-day replacement commitment.

Vendor review

We complete SIG Lite, CAIQ, and custom security questionnaires within five business days. We sign client DPAs and security addenda. A completed SIG Lite and a two-page Security Overview are available on request.

Security contact: [email protected]

Common questions are answered on our FAQ.