Ribbon
Ribbon is an AI recruiter that runs voice and video screening interviews with applicants around the clock, scores each interview against default and custom rubrics, ranks candidates for recruiter review, and syncs the results to 60+ applicant tracking systems.
HireAIScore rates Ribbon 43 out of 100 (grade F, Substantial gaps) under rubric v1.0, last reviewed September 25, 2026. Ribbon ranks 98 of 160 vendors rated in Screening AI, against a category average of 46. That score is drawn from 35 evidence items across 7 rubric criteria for Ribbon — 31 with a cited source, 4 recording that nothing was located.
§ 01 - Company facts
- Legal name
- Ribbon AI Inc.
- Founded
- 2020
- Headquarters
- Canada · CA
- Pricing tier
- Low
- Market side
- Employer-side (AEDT)
- Categories
- ScreeningVideo interview
- Website
- ribbon.ai
These are company details, not findings. They are editable by a verified representative and carry no weight in the score, which is built only from the cited evidence below.
§ 02 - Score breakdown
§ Score breakdown
Category scoring
Weighted contribution shown to the right of each bar.
- 01
Article 11 Technical Documentation
Weight 20%42
+8.4 · category avg 49
- 02
Bias Audit Transparency
Weight 18%38
+6.8 · category avg 41
- 03
FRIA Support
Weight 15%33
+5.0 · category avg 31
- 04
Data Governance Disclosure
Weight 15%50
+7.5 · category avg 53
- 05
Human Oversight Design
Weight 12%55
+6.6 · category avg 56
- 06
Post-Market Monitoring
Weight 12%37
+4.4 · category avg 40
- 07
Customer Documentation
Weight 8%58
+4.6 · category avg 58
Category avg is the mean raw score on that criterion across the 160 Screening AI vendors in scope of this rubric, this one included.
§ 03 - Strongest · weakest
Strongest category
Customer Documentation
Raw score 58 · contributes 4.6 to total.
58 against a 58 category average
Weakest category
FRIA Support
Raw score 33 · contributes 5.0 to total.
33 against a 31 category average
§ 04 - Cited evidence
Download diligence record→§ Evidence
Cited per category
Every score is backed by at least one cited piece of evidence.
Evidence ledger
- Items
- 35
- Documentation
- 22
- Public statement
- 8
- Product feature
- 1
- Absence
- 4
- With a source URL
- 31 of 35
- Source hostnames
- 3
- Fewest items
- 4
- Article 11 Technical Documentation
These figures measure how thoroughly Ribbon was reviewed, not how Ribbon performed — an absence row, recording that nothing was located, is counted like any other item.
Article 11 Technical Documentation
4 items42
- DocumentationCaptured Sep 25, 2026
A public knowledge-base article says the AI reads the full transcript and scores default criteria (Communication, Enthusiasm & Motivation, Skills & Experience, each out of 5) plus custom criteria, returning a reason summary, timestamped positive and negative highlights, and candidate quotes.
- DocumentationCaptured Sep 25, 2026
The privacy policy (updated January 2026) has an EU AI Act section listing human-in-the-loop design, 'documentation of system capabilities and limitations', bias mitigation and logging, but that capabilities-and-limitations documentation is not published.
- DocumentationCaptured Sep 25, 2026
The public DPA says OpenAI models power conversation analysis, summarization and content generation, and LiveKit runs the real-time interview sessions; this is the only public description of the model stack.
- AbsenceCaptured Sep 25, 2026
No model or system card, technical documentation pack, explainability statement, AI governance policy or ISO/IEC 42001 certification was found on ribbon.ai (full sitemap), docs.ribbon.ai (full llms.txt index) or the Sprinto trust center, and none of the trust center's embedded policy titles is AI-specific.
Bias Audit Transparency
5 items38
- Public statementCaptured Sep 25, 2026
The bias-audit page advertises a 2025 audit, '100% bias-free hiring' and '2021/144 compliant' status, but names no auditor, shows no impact ratios, and sends the 'Get access our bias audit report' button to a demo-request form.
- DocumentationCaptured Sep 25, 2026
The DPA (updated 29 September 2025) says Ribbon commissions annual third-party bias audits from Holistic AI, quotes the last audit as finding 'No exceptions were observed' regarding adverse impact, and says gender and ethnicity data may be processed for the audits.
- Public statementCaptured Sep 25, 2026
The homepage shows a 'Bias-free certified' NYC Local Law 144 badge ('Last audited: 2025') and promises 'No bias, no guesswork', although an LL 144 audit reports impact ratios and does not certify a tool as bias-free.
- Public statementCaptured Sep 25, 2026
Releases after the 2025 audit changed what is scored: resume scoring on import (28 August 2026) and feedback-trained scoring whose 'Scores drift toward what you actually reward' (11 September 2026), with no re-audit mentioned.
- AbsenceCaptured Sep 25, 2026
No publicly downloadable LL 144 summary of results (audit date, data period, selection or scoring rates, impact ratios, sample sizes) is linked from ribbon.ai, the bias-audit or regulations pages, the DPA or the Sprinto trust center.
FRIA Support
4 items33
- DocumentationCaptured Sep 25, 2026
The regulations page gives employers region-by-region checklists (California, New York, Colorado, Ontario, Quebec, EU, other) focused on recording consent and privacy; its EU section covers GDPR consent and data-subject requests but not AI Act deployer duties or a FRIA.
- DocumentationCaptured Sep 25, 2026
The DPA commits to 'reasonable assistance' with customers' GDPR Data Protection Impact Assessments and to sharing compliance information on request; this supports a DPIA, not an Article 27 FRIA.
- DocumentationCaptured Sep 25, 2026
The privacy policy says customers 'remain responsible for ensuring appropriate human oversight and compliance' with employment and non-discrimination laws, but provides no deployer templates.
- AbsenceCaptured Sep 25, 2026
No Fundamental Rights Impact Assessment template, AI Act Article 26/27 deployer guidance or instructions for use were found on ribbon.ai, docs.ribbon.ai or the Sprinto trust center.
Data Governance Disclosure
6 items50
- DocumentationCaptured Sep 25, 2026
The privacy policy (updated January 2026) lists the candidate data collected (audio and video recordings, transcripts, AI-generated scores), GDPR legal bases and SCC-based transfers, and gives a typical retention of up to 24 months for interview recordings and transcripts.
- DocumentationCaptured Sep 25, 2026
A public DPA sets out processing details, security measures (TLS in transit, AES-256 at rest, role-based access with MFA, a SOC 2 Type 1 report), 30 days' notice of sub-processor changes, and a sub-processor list with locations that includes OpenAI, AWS, Supabase, LiveKit and Kombo.
- DocumentationCaptured Sep 25, 2026
The Terms of Service (effective 26 March 2025) take a worldwide licence to interview recordings, transcripts and responses to improve the Services 'including training our AI models', which conflicts with the DPA's promise to use data only for candidate evaluation.
- DocumentationCaptured Sep 25, 2026
Ribbon's Sprinto trust center, checked in a real browser, shows SOC 2 as 'In progress' and GDPR as 'Compliant', and lists a Data Retention Policy, a Data Classification Policy and 30+ other policies behind 'Request access'.
https://app.sprinto.com/trust-center/view/5bb8da86-b3b8-4af9-be7b-f83a3980f8c2
- Public statementCaptured Sep 25, 2026
The homepage badge claims 'SOC 2 Type I Certified' with Type II 'in observation', while the homepage FAQ says 'Ribbon is SOC2 Type II compliant', and neither matches the trust center's 'In progress' status.
- Product featureCaptured Sep 25, 2026
A public API endpoint (DELETE /v1/interviews/{interview_id}) lets customers revoke access to an interview's video and audio recordings.
https://docs.ribbon.ai/ribbon-public-api/revoke-access-to-interview-recordings
Human Oversight Design
6 items55
- DocumentationCaptured Sep 25, 2026
Reviewers see the full recording, a timestamped transcript, a structured AI summary, scores with AI reasoning and quoted highlights that jump to the matching moment, and integrity flags, and each reviewer casts their own vote from Strong Hire to Strong No Hire.
- DocumentationCaptured Sep 25, 2026
Integrity monitoring checks the audio environment, response timing, input consistency and interview focus (including looking away from the screen); the docs call it 'not a definitive judgment' and warn that non-native speakers, pauses and poor connections can trigger false positives.
- DocumentationCaptured Sep 25, 2026
The candidate consent screen is an organization-level toggle, and when it is off the 'Interview starts without a consent step'; the default text covers recording and sharing with the hiring organization.
- Public statementCaptured Sep 25, 2026
Ribbon's JazzHR page says that where the ATS supports it, customers 'can also auto-advance or disposition candidates based on clear outcomes', so ATS stage changes can happen automatically from interview results.
- Public statementCaptured Sep 25, 2026
The privacy policy says Ribbon 'does not make autonomous hiring or employment decisions' and, where the law requires it, lets candidates request human review and contest automated outputs through privacy@ribbon.ai.
- Public statementCaptured Sep 25, 2026
Since 11 September 2026, recruiters can disagree with a score and explain why, and Ribbon applies that feedback to future scoring for the whole role.
Post-Market Monitoring
5 items37
- DocumentationCaptured Sep 25, 2026
A public, dated changelog (July to September 2026) records product releases, including scoring changes, but no model versions, bias re-testing results or incident notes.
- AbsenceCaptured Sep 25, 2026
No public status page exists: status.ribbon.ai does not resolve and the ribbon, ribbonai, ribbon-ai and heyribbon statuspage.io subdomains are unclaimed, despite a '99.99% uptime' claim; neither www.ribbon.ai nor app.ribbon.ai serves /.well-known/security.txt.
- DocumentationCaptured Sep 25, 2026
The DPA commits to notifying customers of personal data breaches 'without undue delay' under a formal Incident Response Policy, and names a Data Protection Officer with an email address and phone number.
- Public statementCaptured Sep 25, 2026
The site footer offers only a 'Report a bug' mailto link to support@ribbon.ai (privacy@ribbon.ai appears in the privacy policy); no security, vulnerability-disclosure or AI-incident contact is published.
- DocumentationCaptured Sep 25, 2026
The customer Metrics dashboard covers interview volume, score distribution, candidate location and recruiter activity, and advertises no adverse-impact or fairness monitoring.
Customer Documentation
5 items58
- DocumentationCaptured Sep 25, 2026
A public knowledge base covers interview flows, custom scoring, integrity monitoring, candidate management, teams and permissions, ATS integrations and interview settings, alongside a public API reference.
- DocumentationCaptured Sep 25, 2026
The regulations page gives employers region-by-region compliance guidance, but it covers NYC AEDT rules only in general terms, omits Illinois, and still cites the 'Colorado AI Act' that SB 26-189 repealed and replaced.
- DocumentationCaptured Sep 25, 2026
A public DPA with processing details, security measures and the sub-processor list can be read without logging in.
- DocumentationCaptured Sep 25, 2026
A June 2026 guide takes talent-ops and security reviewers through consent text, access control, review evidence and the ATS handoff, tells them to treat integrity flags as review input, and ends with a procurement checklist.
https://www.ribbon.ai/blog/ai-interview-compliance-security-teams
- DocumentationCaptured Sep 25, 2026
Public pricing lists self-serve plans from $499 a month (billed annually) with a 7-day trial, and reserves 'SOC 2 + security reviews' for Enterprise customers.
§ 05 - Editorial notes
Company overview
Ribbon AI Inc. (ribbon.ai) is a Toronto-based startup, unrelated to Ribbon Communications. Its trust center says it was founded in 2020. It sells an "AI recruiter" for high-volume hiring. The AI interviewer runs voice or video screening interviews in 10+ languages at any hour. It scores each transcript against default and custom rubrics, giving written reasons and quoted highlights, and ranks the candidates. It also flags possible cheating and writes the results back to 60+ ATSs through Kombo. The language models come from OpenAI, which Ribbon lists as a sub-processor. Ribbon announced $8M in funding led by Radical Ventures in March 2025. Self-serve plans start at $499 a month (billed annually), and Enterprise pricing is custom.
Regulatory exposure
Ribbon scores and ranks applicants. NYC employers that use it for hiring decisions are running an automated employment decision tool under Local Law 144, and they must publish the audit summary and give candidates notice themselves. That is harder when Ribbon keeps its 2025 audit behind a demo request, and DCWP has promised tougher enforcement. Under the EU AI Act, Ribbon is a high-risk Annex III(4) system, with obligations now due 2 December 2027. Illinois's HB 3773 notice duty applies now. The AI Video Interview Act applies wherever video mode is used for Illinois roles, because the integrity monitor analyses video for "looking away from the screen". California's FEHA rules require employers to keep records for four years, but Ribbon's privacy policy says it typically keeps recordings and transcripts for up to 24 months. Colorado's SB 26-189 takes effect on 1 January 2027. Three features add to the exposure. The JazzHR integration can auto-advance or reject candidates. Since September 2026, recruiter feedback has changed how the model scores. The integrity flags can misfire on non-native speakers, and Ribbon's own docs say so. Ribbon's regulations page does not mention Illinois and still cites the repealed Colorado AI Act.
Path to a higher score
Publish the Holistic AI Local Law 144 summary instead of gating it: audit and data dates, impact ratios and sample sizes. Re-audit the 2026 changes, resume scoring and feedback-trained scoring, and drop the "100% bias-free" and "Bias-free certified" claims. Make the SOC 2 story consistent: the DPA cites a Type I report, the homepage FAQ claims "Type II compliant" and the trust center says "In progress". The Terms of Service reserve the right to train AI models on interview content, which contradicts the DPA's promise to use data only for candidate evaluation; settle that too. Publish a system card covering how scoring works, the OpenAI dependency, languages, known limitations and accommodations. Make the AI notice mandatory, with default wording that meets LL 144 and Illinois rules and an opt-out or alternative process. Require human review before any automatic rejection. Add a status page, a security.txt file and an AI-incident channel. Update the regulations page for Illinois, Colorado SB 26-189 and the EU AI Act deployer duties in Articles 26 and 27, and include a FRIA template.
§ Regulatory frame
What applies to screening ai.
Treated as high-risk under Annex III §4 when the screening output is decisive. EU AI Act Article 13 transparency obligations apply; deployers must give candidates a way to contest.
§ Compare
Build any comparison→Ribbon against its nearest-scoring peers.
In Screening AI.
§ Others rated in Screening AI
All screening vendors→Ranked 98 of 160 by weighted total under rubric v1.0. The ordering is arithmetic on the rubric and carries no view on which tool suits a given hiring process.
- 95UKG44F
- 96JazzHR44F
- 97Retorio44F
- 98RibbonThis profile43F
- 99HighMatch43F
- 100Wonderlic43F
Conflicts of interest
No vendor pays for placement, scoring, or removal. Casework - the consulting firm that operates this directory - provides paid services to some vendors. Any active or recent (within 24 months) commercial relationship is disclosed on the affected vendor profile and the review is reassigned to an independent reviewer. See the full policy on About.
Casework has no commercial relationship with this vendor.