Sicherheit
Sicherheit & Datenschutz
So schützen wir Ihre Daten: vom Beginn einer Übungssitzung bis lange nach Ihrer Anstellung.
Sicherheitskontrollen
Transport encryption
All traffic served over HTTPS with HSTS enforced (max-age 63072000, includeSubDomains, preload). TLS 1.2+ enforced at the CDN layer.
Data at rest
All database data encrypted at rest by Neon (AES-256). Clerk session tokens stored encrypted. No sensitive data stored in plain text.
Authentication
Managed by Clerk, with industry-standard OAuth2/OIDC flows, brute-force protection, and session expiry. We never handle raw passwords.
Camera data
Camera video is processed entirely in your browser using MediaPipe. No video frames are sent to our servers. No video is stored.
Voice/audio
Live transcription uses your browser's built-in speech recognition. For filler-word and delivery analysis a short audio clip is sent to OpenAI's Whisper API, transcribed, and then discarded; it is not stored on our servers. Voice mode is optional.
Access controls *
Protected API routes require authenticated Clerk session tokens. Unauthenticated requests to protected endpoints return 401. Rate limiting applied to all AI endpoints.
Security headers
HSTS, X-Frame-Options (SAMEORIGIN), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy (camera/microphone self-only), X-XSS-Protection enforced on all responses.
Dependency management
Dependencies reviewed regularly. Production build runs against locked package versions. Critical CVEs addressed as a priority.
* Two endpoints are intentionally public by design: /tools/star-scorer (free STAR answer scorer, IP-rate-limited to 5 requests per hour) and /api/assessment/[token] (assessment invites issued by hiring teams using single-use cryptographic tokens). Neither endpoint exposes personal candidate data.
Unterauftragsverarbeiter
We use the following third-party services to operate the platform. Each is bound by a Data Processing Agreement where required under UK GDPR.
| Dienstleister | Zweck | Standort |
|---|---|---|
| Clerk | Authentication and session management | US (EU data stored in EU region) |
| OpenAI | AI analysis of interview answers and transcripts | US |
| Neon | PostgreSQL database (candidate profiles, sessions) | UK (AWS eu-west-2, London) |
| Vercel | Hosting and edge delivery | Global CDN, origin EU/US |
| Resend | Transactional email (assessment invites) | US |
Ihre Rechte gemäß UK-DSGVO
Sie haben jederzeit das Recht, auf Ihre Daten zuzugreifen, sie zu korrigieren, zu exportieren und zu löschen. Die meisten dieser Aktionen sind direkt über Ihre Profilseiteverfügbar. Für Anfragen, die wir nicht automatisch bearbeiten können, kontaktieren Sie uns unter privacy@aicareermentor.co.uk und wir werden innerhalb von 30 Tagen antworten.
Verantwortungsvolle Offenlegung
If you discover a security vulnerability, please report it to security@aicareermentor.co.uk with a clear description and reproduction steps. We will acknowledge receipt within 48 hours and work to resolve critical issues as a priority. We ask that you do not publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.
Benötigen Sie einen AV-Vertrag oder eine Sicherheitsprüfung?
Unternehmenskunden können einen Auftragsverarbeitungsvertrag, unsere Antworten auf Sicherheitsfragebögen oder ein Compliance-Gespräch mit unserem Team anfordern.
Unternehmens-Team kontaktieren →