Security & Data Handling — last updated: September 2026
The ProofRound Vault is not a marketing promise — it is the architecture of the product. Candidate CVs and job descriptions are treated as radioactive: processed once, in memory, and never written down. This page states exactly what happens to your documents, what we do not do, and the honest limits of our setup, so your security review has real answers.
How candidate documents are handled
In-memory only — zero storageJD and CV text exists solely in the application’s working memory for the seconds it takes to generate your interview kit. It is never written to our database, filesystem, search indexes, backups, or application logs.
Encrypted in transitEvery connection is HTTPS/TLS end to end: your browser to ProofRound, and ProofRound to our AI model providers. Plaintext documents never travel over an unencrypted channel.
Gone when the round endsGeneration requests are stateless. When your round ends, the document text has already gone out of scope and is reclaimed by the runtime. There is nothing to delete, because nothing was ever stored — no retention job, no “delete within 30 days”, no recycled backups holding old CVs.
Generated kits stay with youYour interview kit is returned to your browser session and lives there by default. We do not keep a server-side copy of generated kits, transcripts, or scores either.
What we never do
We never train models on your documents. We do not operate any model training at all, and we instruct providers to process requests solely to serve your request under their API data-processing terms.
We never sell, rent, or share candidate data with third parties for marketing or any other purpose.
We never log document content. Our application logs record operational events (which provider served a request, quota events) — never JD or CV text.
We never use your candidates’ data to build profiles, benchmarks, or datasets.
Subprocessors & hosting
Provider
Role
What touches them
DeepSeek
AI model inference (primary)
JD/CV text — transmitted once over TLS, per-request, for kit generation only; not stored by us.
Moonshot AI
AI model inference (fallback)
Same as above, only if the primary provider fails.
Railway
Application hosting & database
Application and account data (email, company, plan, usage counters). Candidate documents never reach the database layer.
Stripe
Billing
Payment processing. Card numbers go directly to Stripe; we never see or store them.
Data residency, honestly: ProofRound is hosted in the United States (Railway), and our model providers process API requests on their own infrastructure. Candidate document text is processed in memory on our US-hosted servers and transmitted to providers per request — it is not stored, cached, or backed up by us anywhere. If your organization requires EU-only processing, talk to us before uploading documents.
GDPR posture
Roles. You are the data controller for any candidate personal data you process; ProofRound acts as a processor, handling it only on your instructions to deliver the service.
Data minimization by design. We ask for the minimum needed to generate a kit (JD text, optional CV text) and keep none of it. A breach of our servers cannot expose documents that were never written to disk.
Erasure. Candidate documents need no erasure process — they are never retained. Account data (email, company, billing linkage) is deleted within 30 days of a verified request.
No automated decisions. ProofRound produces interview material and scoring support. It makes no hiring decisions; every judgment stays with your team, which also keeps you on the right side of automated-decision rules.
Your obligations. You confirm you have a lawful basis to process candidate data for interviewing, and you inform candidates as required in your jurisdiction.
EU AI Act
ProofRound is built human-in-the-loop by design: it drafts questions, answer keys, and scoring support while every interview and every decision is run and owned by people. We do not perform automated candidate ranking, filtering, or selection. If you operate in the EU, you remain responsible for informing candidates about the use of AI-supported interviewing tools where required — and the Vault makes that conversation easier, because no candidate profile ever accumulates on our side.
Platform security
All traffic served over HTTPS with HSTS; security headers on every response (frame denial, content-type sniffing protection, strict referrer policy).
Passwords hashed with scrypt; password-reset tokens are single-use, expiring, and stored only as SHA-256 hashes.
Browser permissions scoped to the minimum: the interview console requests microphone access for live transcription; camera and geolocation are never requested.
Stripe webhook signatures verified on every billing event.
Responsible use
Please do not paste special-category data (health, political opinions, and similar) into JDs or CVs beyond what the interview genuinely requires, and only process documents you have the right to process.
Contact
Security disclosures, data protection questions, or requests for this statement in review-ready form: [email protected].