Security

How we protect candidate and employer data

This page describes the security practices we use to keep ProvenRemote safe. It is owner-authored and reflects the controls we have implemented. It is not a certification, audit report, or legal guarantee. If you have questions, email security@provenremote.com.

What we protect

ProvenRemote handles candidate profiles, written and audio applications, audition recordings, transcripts, AI scores, employer job posts, screening questions, and billing information. We treat all of this as sensitive and restrict access to the minimum number of people and systems needed to run the service.

Authentication and access control

  • Accounts are protected by email/password or Google sign-in via our authentication provider.
  • Sessions are managed with short-lived tokens and automatic expiration.
  • Database access is controlled by Row-Level Security (RLS) policies, so users can only read or write data that belongs to them.
  • Admin operations require an explicit admin role stored separately from the user profile.
  • Internal functions run with the least privilege required; security-critical helpers are isolated from direct public execution.

Audio and file storage

Audition recordings and screening answers are stored in a private storage bucket. They are never made publicly accessible. They are served only through short-lived, signed links to the candidate, to authorized reviewers, and to the specific employer the candidate has been matched with. Audio is not downloaded or stored on our edge servers; it is streamed directly from the storage layer.

Encryption

All traffic between your browser and ProvenRemote is encrypted in transit using TLS. Data at rest is encrypted by our cloud database and object storage providers. Credentials, API keys, and signing secrets are stored in managed secret systems, not in application code or version control.

AI processing

Written answers and audio transcripts are sent to our AI provider for scoring and transcription. We do not allow the AI provider to use your content to train its models. We only send the data needed for the specific task, and we store returned scores and transcripts in our own database. No AI provider has direct access to your account or database.

Payments

We do not store employer card numbers. Payment information is collected and processed by our payment processor according to their security standards. We retain only the minimum billing record needed for invoicing and support.

Monitoring and logging

We log authentication events, data access, and administrative actions. Logs are retained for a limited period and used for security investigations, debugging, and abuse prevention. We review access patterns and respond to anomalies.

Incident response

If we discover a security incident that affects personal data, we will notify affected users and any required regulators without undue delay. Employers will be notified if their candidate data is involved. Our first response is to contain the incident, preserve evidence, and remediate the root cause.

What you can do

  • Use a strong, unique password and do not share your login.
  • Treat your job-post management link as confidential.
  • Report suspicious messages or account access to security@provenremote.com.
  • Keep your browser and devices up to date.

Reporting security issues

If you find a vulnerability or security concern, email us at security@provenremote.com. We will acknowledge receipt, investigate, and keep you informed of meaningful outcomes. We will not take legal action against researchers who report issues in good faith and do not exploit or publicly disclose them before we have a chance to fix them.

Changes

We update this page as our practices evolve. The date at the top reflects the last material change. For the legal commitments that govern data processing, see our Data Processing Addendum and Privacy Policy.

Last updated: 16 August 2026