Security & data handling

What happens to a candidate's interview.

Written for the person your Head of Talent forwards this to. It names our sub-processors, states our retention and deletion behaviour, and is explicit about the certifications we do not have — because the alternative is you finding out in week three.

The commitments that shape everything else

The AI screens, a human decides

The product ranks candidates and evidences why. It cannot advance or reject anyone, and there is no configuration that lets it. This is a product constraint, not a policy — and it is what keeps automated screening on the right side of the EU AI Act, which classes employment screening as high-risk, and NYC Local Law 144.

Every score traces to evidence

Each score carries the rubric line it was scored against, the candidate's verbatim words, and the timestamp in the recording. We also record which model, prompt version and rubric produced it. When a candidate asks why — or a regulator does — the answer exists without re-running a model that has since changed.

Candidates are told before, not after

What is recorded, who sees it, how long it is kept, and how to have it deleted — all on the page before the interview opens, with consent as an explicit action that is timestamped and versioned against the notice they actually saw.

Practice and hiring are walled off

MockLive also sells interview practice to individuals. No practice session is ever visible to an employer, and no screen is ever visible to anyone outside the org that paid for it. They are separate data paths with separate authorisation.

Retention and deletion

  • Recordings and transcripts are deleted 12 months after a screen completes, by default. You can set this anywhere from 30 days to 3 years for your organisation.
  • Deletion is performed by a scheduled job against a per-screen expiry stamped at completion — not by a bucket rule that cannot express per-customer retention, and not by hand.
  • Scores and the rubric trace survivethe media deletion. That is deliberate: you need to answer “why was this person not advanced” long after the recording is gone, and a score with its rationale does that without keeping someone's face.
  • The candidate's authentication identity is deleted with their recording. A row saying a named person interviewed at a named company on a named date is exactly the record the promise was about.
  • A candidate can request erasure at any time, before or after the deadline. Route it to support@mocklive.ai or ask us and we will action it directly.

Who can see what

Sub-processors

Named, not described by category. None are permitted to train models on your candidates' content.

ProviderWhat it doesWhat it receivesRegion
Google Cloud (Cloud Run, Firestore, Cloud Storage, Firebase Auth)Hosting, database, recording storage, and sign-in.Everything: account records, screens, transcripts, recordings.us-central1 (United States)
DeepgramSpeech-to-text. Receives interview audio, returns text.Candidate audio.United States
InworldSpeech synthesis. Receives the interviewer's written lines only.Never receives candidate answers, recordings or transcripts.United States
Google (Gemini API)Conducts the interview and scores the transcript against your rubric.Job description, rubric, transcript.United States
Dodo PaymentsTakes card payments as merchant of record.Billing contact and card details. We never see a card number.United States / EU

All processing happens in the United States. If you have EU candidates, the cross-border transfer is disclosed in our privacy policy. Ask us about transfer mechanisms before you screen EU candidates — see the next section for where that stands.

What we can't claim yet

A security page where everything is green is a security page nobody should believe. These are the questions we get asked and cannot answer with a yes.

Are you SOC 2 certified?

No. We have not completed a SOC 2 Type I or Type II audit, and we will not imply otherwise on a page like this one. If SOC 2 is a hard procurement gate for you, tell us — it changes our timeline, and we would rather know than lose the deal quietly.

Do you have signed DPAs with your sub-processors?

Not yet with all of them. All the providers above offer standard DPAs and we are working through them. Ask us where a specific one stands and we will tell you the truth rather than a status colour.

Have you had a penetration test?

No third-party penetration test has been performed. What exists instead: default-deny authorisation rules on every data path, an append-only audit ledger for anything that moves money, and per-request permission checks resolved from the database rather than from a cached token.

Do you have an annual bias audit for NYC Local Law 144?

Not yet, because we have not yet run enough screens to produce a meaningful one. If you hire in New York City this matters to you and to us: the law requires an independent audit published before an automated employment decision tool is used. Talk to us before you screen NYC candidates so we can sequence this properly.

A question this page doesn't answer?

Send it over. We answer security questionnaires directly, and we would rather tell you a no early than discover it together in procurement.

support@mocklive.ai