Skip to content
Book a demo
  1. Home
  2. Legal
  3. Security

Security

Alert Hire holds your candidates' CVs, their interview answers and the scores. This page is what we do to protect them, written so you can put it in front of a client or your IT lead.

Updated 9 September 2026. Questions or a security questionnaire: admin@alertai.com.au.

At a glance

The short version

Hosted in Sydney

Candidate records, CVs, answers and scores live in a database and file store in Sydney, Australia. Backups stay in Australia.

Encrypted

Everything is encrypted in transit and at rest. CV files sit in a private store reached only through short-lived signed links.

Workspaces kept apart

Each agency's workspace is separated from every other at the database level. Your candidates are never visible to another agency.

No model training

Candidate CVs and answers are never used to train AI models, by us or by our AI provider, under our agreement with them.

Hosting and infrastructure

The web app is served by Vercel from Sydney; requests may pass through its global network. The database and file store that hold candidate data are hosted in Sydney, Australia, and backups are kept on servers in Australia. Every change to the database goes through reviewed migrations, and access to production systems is limited to the people who run the service.

Encryption and access

  • Data is encrypted in transit and at rest.
  • CV files are kept in a private store and reached only through short-lived signed links, so a file URL cannot be shared or guessed.
  • Interview links carry a signed token, and only a hash of the token is stored, so a copy of the database does not give access to an interview.
  • Each person in your workspace has their own sign-in; accounts are not shared. You are responsible for removing people who leave, and you can do so from the app.

AI processing

  • The AI model that reads CVs, writes interview questions, asks follow-ups and scores answers is provided by Anthropic in the United States. The text of the CV or the answers is sent for that call and is not used by Anthropic to train models under our agreement with them. We do not send more than the step needs.
  • Every score in a report comes with the evidence it was based on, quoted from the CV or the answer, so a recruiter can check it. The recruiter records the decision; the software does not.
  • Sensitive information that turns up in a CV or an answer is not used to score the candidate.

Providers

We use a small number of providers for particular steps, and disclose the minimum each one needs.

ProviderWhat it doesWhat it sees
Anthropic (US)AI model for reading CVs and scoring answersCV text and interview answers for the call; not used for training
Resend (US)Delivers the emails we sendCandidate name, email address and the message text
Stripe (US)Subscription billing for agenciesAgency billing details only; never candidate data
Sentry (US)Error reports when something breaksStripped of candidate text where we can; may include a name or email
VercelServes the web app from SydneyRequests in transit

Data lifecycle

  • Each agency sets a retention period for candidate data, between 3 and 24 months from when a job is closed. When it passes, the CV files, extracted text, answers, scores and summaries are deleted automatically.
  • Interview links expire on the date shown in the invitation.
  • You can export or erase a single candidate's data on request at any time.
  • When your agreement ends you can export your reports for 30 days. After that the workspace and its candidate data are deleted, apart from what the law requires us to keep.

Incident response

If we become aware of a data breach affecting your candidates, we will tell you without undue delay and give you what you need to meet your own obligations. Where the breach is likely to result in serious harm, we will notify the affected agency, the people affected and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

Cookies

The app uses cookies only to keep you signed in. Candidate interview pages set no cookies and are marked so search engines do not index them. This website sets no cookies and runs no advertising or tracking scripts.

Certifications

We are an early-stage company and do not yet hold ISO 27001 or SOC 2 certification. We will complete your security questionnaire, walk your IT lead through the architecture, and confirm the current provider list on request.

Reporting a vulnerability

If you find a security issue in Alert Hire or this website, email admin@alertai.com.au with "Security vulnerability" in the subject. We will acknowledge within two business days, keep you informed, and not take action against good-faith research that avoids accessing other people's data and gives us reasonable time to fix the issue.