Employer due diligence

Security overview

One-page summary for pilot procurement — infrastructure, controls, AI handling, and subprocessors.

Prefer FeedbackAI in Google? Add us as a preferred source for India tech hiring and match explainers.

Draft summary · Aug 2026 · For full legal terms see Privacy Policy and DPA on request

Back to Security & trust

What we protect

  • Candidate PII — name, email, phone, resume, work history; visible to the candidate and authorized employer users on their jobs.
  • Assessment data — responses and AI rubric scores; scoped to the candidate and employer interviewers on that role.
  • Employer account data — org users, job postings; role-scoped access only.

Infrastructure

Application on Vercel (TLS), primary database on MongoDB Atlas (India), files and weekly backups on AWS S3 (ap-south-1 Mumbai), email via Resend, AI inference via OpenAI (United States). EU/UK prospects receive a DPA with SCCs/IDTA before candidate PII import.

Controls (shipped)

  • HTTPS/TLS; AES-256 at rest on S3; provider encryption at rest on Atlas
  • NextAuth sessions; org-scoped roles (ORG_ADMIN, INTERVIEWER, CANDIDATE)
  • Email sign-in codes required for hiring-team accounts (org admin and interviewer)
  • reCAPTCHA on sensitive public flows; CRON jobs require bearer token
  • CSP, HSTS, X-Frame-Options; Zod validation on high-risk API routes

AI data handling

Assessment prompts and redacted professional resume slices are sent to OpenAI for generation and evaluation (API inference). Candidate data is not used to train OpenAI models on the API / Business tier. AI scores are decision support — human hiring decisions remain with your team (see Terms of Service).

Security testing

  • Internal weekly vulnerability scanning — API auth review plus npm audit in CI
  • Last structured OWASP Top 10 (2021) review: 31 July 2026 — 0 open critical or high findings
  • Public scanners employers can re-run: Mozilla Observatory (headers / CSP) and Qualys SSL Labs (TLS). These are automated checks, not a penetration test.
  • Third-party penetration test: planned. Written report available to employers on request when completed.

Honest boundaries

  • Not a regulated background-check provider
  • No SOC 2 Type II yet — this page is the interim due-diligence summary
  • No on-prem or customer-managed encryption keys today

Subprocessors: Privacy Policy §4.5. DPA: request by email.

FeedbackAI for Hiring Teams — Match-Ranked Applicants & AI Assessments