Skip to main content

Security at HireFlow-AI

How we protect your account and your practice data, in plain language, including what we have and have not done.

Last updated: 6 October 2026

1. Our approach

Interview practice involves sensitive material: your resume, your spoken answers and sometimes your face. We try to collect as little as possible, keep it for as short a time as possible, and protect what we keep. Security and privacy were requirements from the start of the project, not an add-on.

2. Your account

  • Passwords are stored only as a salted, slow hash (bcrypt), never as plain text, and cannot be read back by us.
  • Signing up needs a 6-digit code sent to your email, which expires after ten minutes and allows only a few attempts.
  • Sign-in sessions are short-lived and renew automatically. The renewal token is kept in a cookie that scripts on a page cannot read, and each token can be used once; reusing an old one signs every session out as a precaution.
  • After repeated wrong passwords, an account is locked for a short time. Sign-in and code requests are rate-limited.
  • Administrator accounts need their password and a fresh emailed code at every sign-in, and their access is checked against our records on every request, so removing an administrator takes effect immediately.
  • Closing the browser signs you out.

3. Your data

  • Only you can open your interviews, results and files. Authorised administrators can review interviews for support, quality and abuse prevention, and their actions are written to an audit log.
  • Resumes and recordings are deleted automatically 30 days after upload. Security log entries are deleted after 12 months.
  • You can delete your account in Profile & Settings. Your profile, interviews, transcripts, files and notifications are erased immediately and permanently.
  • The resume checker and the HireFlow Helper chat do not store what you submit.
  • We do not sell personal data, use it for advertising, or train our own models on your interviews.

4. Camera, microphone and recordings

  • Your face is analysed inside your browser to estimate eye contact and expression. The video frames used for this are not uploaded.
  • Recording is off unless you tick the consent box in the interview lobby.
  • If your browser cannot turn speech into text itself, short audio clips are sent for transcription and are not kept.

5. Infrastructure

  • All traffic uses HTTPS, with certificates issued and renewed automatically, and browsers are told to keep using HTTPS.
  • Every request is checked and validated on our server before it reaches the database, and files you upload are checked for type and size.
  • The database accepts connections only from our own server, and the server's firewall allows only web and administration traffic.
  • The database is backed up every night and backups are kept for 14 days. A new version of the site is released with a database backup first, and is rolled back automatically if it fails its health check.

6. AI and your content

Our AI features send the text they need (for example your answers or resume) to our AI provider, Google's Gemini API, to produce a response. Instructions we give the AI tell it to treat anything you or a student submit as data, never as commands. This reduces, but cannot completely remove, the risk of someone trying to manipulate an AI system. See the Privacy Policy for what is sent and the Responsible AI page for how to read AI results.

7. What we do not claim

HireFlow-AI is a young product built by a small team. We have not yet been independently audited or certified (for example SOC 2 or ISO 27001), and no online service can promise perfect security. We do not claim to protect against every possible attack. We would rather tell you plainly what we do than overstate it.

8. Reporting a problem

If you think you have found a security problem, or you are worried about your account, please tell us through the contact page with as much detail as you can. Please do not publish a vulnerability before we have had a reasonable chance to fix it, and do not access other people's data while testing.

Questions about this page?

Send us a message through the contact page and we will get back to you.

See also: Terms · Privacy · Security · Cookies · Responsible AI