Trust and security

The short version: candidate data stays in North America with a small set of named providers, is encrypted in transit and at rest, is reachable only by the workspace that created it, and is deleted on a schedule the employer controls.

Last updated 7 September 2026.

Where data lives

  • Application hosting: Vercel (United States).
  • Database (candidate records, transcripts, assessments): Prisma Postgres (United States).
  • Recordings (screen, audio, camera): Cloudflare R2 object storage (Western North America region).
  • AI processing (the interview conversation, speech recognition, speech synthesis, the written assessment): OpenAI, under terms that do not use the data to train models.

The code editor's software files (Monaco) load from jsDelivr, a public content delivery network; it sees the candidate's IP address and browser type, never interview content. The full list, with what each provider does, is on the subprocessors page.

Protection

  • Encrypted in transit (TLS) and at rest by our storage providers.
  • Invitation links are personal to one candidate, expire on the date the recruiter sets, and cannot be used to start or re-take the interview once it is submitted; the link secret is stored only as a hash plus an encrypted copy so the recruiter can re-send it. Review links for hiring managers are read-only and expire after 30 days.
  • Access is scoped to the workspace that created the screening. Candidates never see the assessment, the score, the session flags or the recruiter's notes.
  • The candidate's browser is treated as untrusted: the server owns the transcript, the clock and the interview state.
  • Recruiters sign in with Google. Product analytics is switched off on candidate and review-link pages. Two-person workspace roles are being added; single sign-on (SAML) is planned for larger customers.

Retention and deletion

Each workspace sets a retention period (180 days by default). A scheduled job removes candidate names, emails, recordings, transcripts and written assessments when it ends. A recruiter can delete any candidate earlier, and we complete candidate deletion requests within 30 days.

Incidents

If we become aware of a breach affecting candidate data, we notify the affected employers without undue delay with what happened, what data was involved and what we are doing, so they can meet their own notification duties. The full incident response policy has the timelines and what a notice contains.

Assurance

We do not yet hold a SOC 2 or ISO 27001 report. We complete security questionnaires (SIG Lite, CAIQ or your own) on request, we publish this page and our data processing agreement, and we will share a third-party penetration test summary when it is complete. Ask at support@interviewstack.io.

Responsible disclosure

Found a vulnerability? Email support@interviewstack.io with the details. We acknowledge within two business days and do not pursue researchers acting in good faith. Scope, rules and fix targets are in the responsible disclosure policy.

Trust and security | InterviewStack for Recruiters