Incident response
What happens when something goes wrong with the security or availability of screening data: how we find out, what we do, and what you hear from us.
Last updated 9 September 2026.
What counts as an incident
- Data incident: unauthorised access to, disclosure of, alteration of or loss of candidate or employer data, including a credential (an invite link, a review link, an API key, a webhook secret) reaching someone it was not meant for.
- Availability incident: the interview, the review page or the API is unavailable or degraded for longer than a few minutes; for a candidate in the middle of an interview, any outage counts.
- Integrity incident: a defect that changes a score, a transcript or a flag after the fact, or shows one candidate's data on another's page.
How we detect
Provider status notifications (Vercel, Prisma, Cloudflare, OpenAI, Resend), automatic retries of failed webhook deliveries every 15 minutes, a nightly retention sweep that logs any failed deletion, stranded-interview detection on the review page, error logs, reports from employers and candidates at support@interviewstack.io, and researcher reports under our responsible disclosure policy.
What we do
- Triage, target 24 hours from awareness. Confirm, classify (data, availability, integrity), assess who is affected.
- Contain. Revoke or rotate the affected credentials: review links, API keys and webhook secrets can each be rotated or revoked on their own; an exposed invite link is cancelled by deleting and re-inviting the candidate, and every invite link stops working once the interview is submitted. Disable the affected path. Keep the records we hold.
- Notify affected employers without undue delay after we become aware of a data incident: a first notice within 24 hours of confirming it, even when facts are incomplete, and updates as they firm up. By email to the workspace owner with: what happened, when, which candidates and data categories are involved, what we have done, what we recommend they do, and a contact. We update as facts change. Employers are the data controllers and carry their own notification duties to candidates and regulators; our notice is written so they can meet them.
- Recover. Restore service, verify data integrity against the stored transcript and assessment (the server, not the browser, is the authority for both).
- Review, target 10 business days. Root cause, what would have caught it earlier, the fix and its verification, recorded internally and summarised to affected employers on request.
What we will not do
We do not notify candidates directly on an employer's behalf unless the employer asks us to, and we do not disclose one employer's incident to another. We keep the records we hold (interview data, our own model-call logs, our database) as long as needed to establish what happened, and pull provider logs promptly where their retention is short.
Contact
support@interviewstack.io for anything urgent. Security questionnaires and past revisions of this policy are available on request.