Security at NeuralHire
Your interview data is sensitive. We take security seriously and apply industry-standard practices to protect everything you share with us.
Our security practices
Encryption in transit
All data transmitted between your browser and our servers is encrypted with TLS 1.2 or higher. Unencrypted HTTP connections are automatically redirected to HTTPS.
Encryption at rest
Databases, file storage, and backups are encrypted at rest using AES-256. Encryption keys are managed through a dedicated key management service.
Authentication
Account authentication is handled by Clerk, which provides secure session management, multi-factor authentication (MFA), and brute-force protection.
Secure payments
All payment processing is handled by Stripe — a PCI DSS Level 1 certified provider. NeuralHire never stores or processes raw card numbers.
Least privilege access
Internal access to production systems is restricted to authorised personnel only, using role-based access controls and multi-factor authentication.
Regular audits
We conduct periodic security reviews of our infrastructure, dependencies, and code. Third-party dependencies are monitored for known vulnerabilities using automated tooling.
Your data and AI processing
Interview transcripts, voice recordings, and video frames are processed by OpenAI's API to generate feedback and responses. We have a data processing agreement with OpenAI. Your data is used only to serve your request — not to train OpenAI's models.
Resume text and job descriptions you upload are stored securely and used exclusively to personalise your interview session. They are never shared with employers or third parties.
You can permanently delete all your data at any time from the Settings page in your dashboard.
Responsible disclosure
If you believe you have found a security vulnerability in NeuralHire, please report it responsibly. Email us at neuralhire@softartificial.com with a description of the issue and steps to reproduce it. We will acknowledge your report within 48 hours and aim to resolve confirmed issues within 30 days.
Please do not publicly disclose vulnerabilities before we have had a chance to address them.