Public AI Governance Documentation
NIST AI 600-1 Risk Map
A public map of generative AI risk categories to HireProxy's product context.
Last reviewed: July 6, 2026
NIST AI 600-1 identifies risk categories that can be novel to or intensified by generative AI. This document maps those categories to HireProxy's use case and current or planned controls.
1. CBRN Information or Capabilities
Applicability: Very low.
HireProxy is a career-preparation product and is not designed to provide chemical, biological, radiological, nuclear, weapons, or cyber-offensive instruction.
Current controls:
- Product scope is limited to career background, role fit, interview prep, and interview practice.
- Off-topic public career-agent questions are redirected to professional background.
- Provider safety systems remain in place.
Reasonable next action: Include off-topic harmful-content prompts in the small evaluation set.
2. Confabulation
Applicability: High.
This is HireProxy's most important AI quality risk. False or unsupported career facts could affect a candidate's reputation or a recruiter's perception.
Current controls:
- AI instructions prohibit new facts and require uncertainty fallback.
- Public career-agent responses are grounded in candidate-provided data.
- Story-based outcome claims require story evidence.
- Employer and client relationships are explicitly separated.
- High-risk facts such as metrics, certifications, dates, client names, and tools require explicit evidence.
- Interview evaluation prompts evaluate only the transcript and saved prep.
Reasonable next action: Create and run a grounding/confabulation eval set before major prompt or model changes.
3. Dangerous, Violent, or Hateful Content
Applicability: Low.
HireProxy's intended context is professional career preparation. Still, public chat surfaces can receive arbitrary input.
Current controls:
- Product scope limits responses to professional background and interview prep.
- Provider safety systems remain in place.
- Report-abuse intake is available.
Reasonable next action: Add harmful-content examples to the eval set and incident categories.
4. Data Privacy
Applicability: High.
HireProxy processes career history, resumes, job descriptions, voice transcripts, practice answers, recruiter conversations, and account data.
Current controls:
- Public privacy and data retention pages describe data uses and retention.
- Sensitive account, admin, interview, upload, auth, and API paths are excluded from session diagnostics.
- Practice audio is processed for transcription and speech, but saved practice records store transcript, metrics, and feedback rather than saved audio.
- Tenant-owned data uses Row Level Security where user access is allowed.
- A user data export path is available for core candidate-provided profile data, and deletion paths are available.
Reasonable next action: Maintain a vendor review record and confirm provider data-use settings before enterprise or outplacement sales.
5. Environmental Impacts
Applicability: Low to medium.
HireProxy uses third-party AI APIs rather than training or hosting foundation models.
Current controls:
- No custom model training or fine-tuning is performed.
- Bounded requests, scoped AI instructions, rate limits, and output limits reduce avoidable model usage.
- Lower-cost/smaller models are used where appropriate.
Reasonable next action: Track AI cost and request volume as a proxy for resource use.
6. Harmful Bias or Homogenization
Applicability: Medium.
HireProxy is not a hiring decision tool, but AI-generated career framing can still shape how candidates are represented.
Current controls:
- Terms state that HireProxy is not an employment selection, ranking, or rejection system.
- Candidate controls the underlying career data and final published story choices.
- AI is instructed to avoid protected-characteristic assessments.
- Product copy positions Interview Mode as preparation and practice.
Reasonable next action: Add a quarterly review of coaching tone, gap framing, and protected-characteristic handling.
7. Human-AI Configuration
Applicability: High.
Users and visitors need to understand which outputs are AI-generated and how much to rely on them.
Current controls:
- Candidate sites disclose that the assistant is AI-powered and can make mistakes.
- Terms state that users are responsible for candidate-provided content and visitors should independently confirm information.
- Raw practice answers are private unless the user chooses to refine or publish them.
Reasonable next action: Keep disclosures visible when adding new AI surfaces or new partner/customer experiences.
8. Information Integrity
Applicability: High.
The product represents professional background. Incorrect claims, omissions, or manipulative prompts can affect trust.
Current controls:
- Evidence-oriented prompt rules.
- Report-abuse intake for false or misleading information.
- Candidate edit and unpublish controls.
- Public risk assessment and incident response pages.
Reasonable next action: Track confirmed false-fact incidents and corrective actions in the incident register.
9. Information Security
Applicability: High.
HireProxy is multi-tenant and processes private career, interview, and account data.
Current controls:
- Supabase Auth and Row Level Security for user-owned data.
- Privileged operations are confined to server-side execution.
- Service endpoints use authentication, ownership checks, entitlement checks, input limits, and rate limits where relevant.
- Sentry captures exceptions without intentionally exposing raw errors to users.
- Sensitive telemetry paths are blocked from session diagnostics.
Reasonable next action: Add periodic security review for new data stores, access policies, and privileged server-side operations.
10. Intellectual Property
Applicability: Medium.
Users may upload resumes, job descriptions, and career materials that they own or have permission to use.
Current controls:
- Terms prohibit uploading confidential, proprietary, or third-party materials unless the user has the right to use them with the service.
- Candidates retain ownership of their uploaded and provided content.
Reasonable next action: Add a short reminder near job-description upload or public-start flows if enterprise users begin uploading sensitive materials.
11. Obscene, Degrading, and/or Abusive Content
Applicability: Low to medium.
Public candidate sites can receive arbitrary text input from visitors.
Current controls:
- Provider safety systems remain in place.
- Public report-abuse path exists.
- Product scope is professional career discussion.
Reasonable next action: Categorize abusive-content reports and add repeated patterns to AI instructions or product controls.
12. Value Chain and Component Integration
Applicability: High.
HireProxy depends on AI, infrastructure, auth, storage, email, payments, monitoring, telemetry, and bot-protection vendors.
Current providers:
- Anthropic for AI generation.
- OpenAI for transcription and speech generation.
- Supabase for database, auth, and storage.
- Vercel and Vercel KV for hosting, serverless runtime, and rate limiting.
- Resend for transactional email and abuse-report delivery.
- LemonSqueezy for payments.
- Sentry for error monitoring.
- LogRocket for privacy-constrained diagnostics on non-sensitive marketing surfaces when enabled.
- Cloudflare Turnstile for bot-prevention checks on public start flows.
Reasonable next action: Maintain a vendor register with purpose, data categories processed, key settings, and review date.