Written for the person your Head of Talent forwards this to. It names our sub-processors, states our retention and deletion behaviour, and is explicit about the certifications we do not have — because the alternative is you finding out in week three.
The product ranks candidates and evidences why. It cannot advance or reject anyone, and there is no configuration that lets it. This is a product constraint, not a policy — and it is what keeps automated screening on the right side of the EU AI Act, which classes employment screening as high-risk, and NYC Local Law 144.
Each score carries the rubric line it was scored against, the candidate's verbatim words, and the timestamp in the recording. We also record which model, prompt version and rubric produced it. When a candidate asks why — or a regulator does — the answer exists without re-running a model that has since changed.
What is recorded, who sees it, how long it is kept, and how to have it deleted — all on the page before the interview opens, with consent as an explicit action that is timestamped and versioned against the notice they actually saw.
MockLive also sells interview practice to individuals. No practice session is ever visible to an employer, and no screen is ever visible to anyone outside the org that paid for it. They are separate data paths with separate authorisation.
Named, not described by category. None are permitted to train models on your candidates' content.
| Provider | What it does | What it receives | Region |
|---|---|---|---|
| Google Cloud (Cloud Run, Firestore, Cloud Storage, Firebase Auth) | Hosting, database, recording storage, and sign-in. | Everything: account records, screens, transcripts, recordings. | us-central1 (United States) |
| Deepgram | Speech-to-text. Receives interview audio, returns text. | Candidate audio. | United States |
| Inworld | Speech synthesis. Receives the interviewer's written lines only. | Never receives candidate answers, recordings or transcripts. | United States |
| Google (Gemini API) | Conducts the interview and scores the transcript against your rubric. | Job description, rubric, transcript. | United States |
| Dodo Payments | Takes card payments as merchant of record. | Billing contact and card details. We never see a card number. | United States / EU |
All processing happens in the United States. If you have EU candidates, the cross-border transfer is disclosed in our privacy policy. Ask us about transfer mechanisms before you screen EU candidates — see the next section for where that stands.
A security page where everything is green is a security page nobody should believe. These are the questions we get asked and cannot answer with a yes.
No. We have not completed a SOC 2 Type I or Type II audit, and we will not imply otherwise on a page like this one. If SOC 2 is a hard procurement gate for you, tell us — it changes our timeline, and we would rather know than lose the deal quietly.
Not yet with all of them. All the providers above offer standard DPAs and we are working through them. Ask us where a specific one stands and we will tell you the truth rather than a status colour.
No third-party penetration test has been performed. What exists instead: default-deny authorisation rules on every data path, an append-only audit ledger for anything that moves money, and per-request permission checks resolved from the database rather than from a cached token.
Not yet, because we have not yet run enough screens to produce a meaningful one. If you hire in New York City this matters to you and to us: the law requires an independent audit published before an automated employment decision tool is used. Talk to us before you screen NYC candidates so we can sequence this properly.
Send it over. We answer security questionnaires directly, and we would rather tell you a no early than discover it together in procurement.
support@mocklive.ai