Security and Candidate Data Protection
Interview recordings, transcripts, and scorecards are sensitive by nature. The Cognitive treats candidate data with the controls enterprise hiring teams expect: encrypted in transit and at rest, access-controlled by role, logged, and retained under clear policies - with candidates informed about what is collected and why.
Core practices
- Encryption in transit (TLS) and at rest for recordings, transcripts, and candidate records.
- Role-based access: hiring team members see only the roles and candidates they're granted.
- Integrity logging: interview-session events (tab switches, camera-off, identity signals) are logged with the recording for auditable evaluations.
- Data retention on your terms: retention windows and deletion on request, aligned to your policies and applicable law (GDPR for EU candidates).
- Vendor hygiene: production access is restricted, credentialed, and audited; secrets are never in client code.
Candidate transparency
- Candidates know they are interviewing with an AI interviewer before the session starts.
- Recording and evaluation are disclosed up front; candidates see what the interview assesses.
- Candidate data is used to evaluate them for the role they applied to - not to train unrelated models or be resold.
Frequently Asked Questions
Where is interview data stored and who can access it?
Interview recordings, transcripts, and scorecards are stored encrypted at rest and served over TLS. Access is role-based within your team, and The Cognitive's own production access is restricted and audited. Data exports are available for your compliance workflows.
How long is candidate data retained?
Retention follows your configured policy and applicable law. Candidates can request deletion, and EU candidate data is handled in line with GDPR principles - lawful basis, purpose limitation, and the right to erasure.