Security and stewardship

Use AIHire with a clear security boundary.

AIHire provides application-level controls and transparent handling guidance. The deployment owner remains responsible for infrastructure, access, retention, and legal obligations.

Application practices

Controls you can inspect in the product.

Protected account flows

Authentication and role claims are handled by the backend. Workspace access should be checked server-side, not trusted from a browser label.

Data minimization

Upload only the documents needed for the analysis. The interface distinguishes stored account data, uploaded content, and derived matching evidence.

Deployment-aware controls

Transport encryption, secret management, backups, storage permissions, logging, and retention depend on the deployment environment and must be configured by its operator.

Human review boundaries

AI outputs are presented as screening evidence. They are not a security or compliance certification and should not be used as the sole basis for a consequential decision.

Before uploading sensitive data

  • Confirm that your organization has a lawful basis and permission to process the document.
  • Remove unrelated personal data where it is not needed for the role or analysis.
  • Use the configured deployment URL and verify who can access the workspace.
  • Review retention and backup settings with the deployment operator.

Do not treat the UI as a guarantee

A browser state, badge, or report cannot prove that a production environment is secure. Protect API credentials, configure HTTPS, restrict storage access, and monitor the backend before using real applicant data.

Found a security issue?

Share the affected route, environment, and a safe description. Do not include passwords, tokens, resumes, or other private data in an initial report.

Email [email protected]