Public AI Governance Documentation
NIST AI RMF Alignment
How HireProxy maps current controls and next steps to Govern, Map, Measure, and Manage.
Last reviewed: July 6, 2026
NIST describes the AI RMF Core as four functions: Govern, Map, Measure, and Manage. This document maps HireProxy's current controls and reasonable next steps to those functions. It is not a certification or external audit.
Govern
NIST intent: Establish accountability, policies, roles, risk culture, documentation, incident processes, and third-party risk management.
Current HireProxy controls:
- Broadlake Technologies LLC is the accountable operator.
- Public privacy, data retention, terms, AI risk assessment, and incident response pages describe platform-level governance.
- Model identifiers are centralized so model upgrades can be reviewed in one place.
- Terms prohibit fabricated credentials, impersonation, unauthorized voice recording, and undisclosed live-interview assistance.
- Candidate sites include an "About this assistant" disclosure that AI can make mistakes and final details should be confirmed with the candidate.
- Core candidate-provided profile data can be exported, edited, unpublished, or deleted.
- Sensitive product surfaces are excluded from session diagnostics.
Reasonable next controls:
- Maintain this AI governance package as the public control narrative.
- Keep a quarterly AI risk review log.
- Add an AI system inventory owner field and review date for each system card.
- Maintain the vendor/model register before provider or model upgrades.
- Keep an incident register for AI quality, privacy, security, provider, and voice-practice incidents.
Map
NIST intent: Understand the system context, intended use, users, benefits, risks, affected parties, data context, and deployment environment.
Current HireProxy controls:
- Intended use is limited to candidate-owned career representation, role-fit analysis, interview preparation, and practice.
- Public terms state that HireProxy is not an automated employment selection, ranking, or rejection system.
- Sensitive or higher-risk employment decisions are explicitly reserved for humans outside the product.
- Public and private data boundaries are documented: career-site content can be public, while raw interview practice answers are private by default.
- Interview Mode maps context by company, role, interview stage, interviewer context, saved prep, transcript, and delivery metrics.
- Public career agents are scoped to one tenant's candidate data.
Reasonable next controls:
- Add a short pre-release risk review for any new AI surface.
- Keep system cards updated when an AI surface, model, provider, or data flow changes.
- For future B2B or outplacement sales, document customer-specific context, administrator responsibilities, and any additional human review expectations.
Measure
NIST intent: Evaluate, test, monitor, and document AI risks, including trustworthiness, privacy, security, transparency, fairness, and reliability.
Current HireProxy controls:
- Automated tests cover accuracy guardrails, privacy telemetry controls, interview prep, public discovery, and rehearsal behavior.
- Error monitoring captures application exceptions and provider failures.
- Usage events track interview prep and rehearsal completion.
- Report-abuse intake allows external users to flag misleading or false candidate-site content.
- Voice features enforce ownership checks, rate limits, entitlement checks, and input size limits.
- The voice feedback architecture preserves full detailed scoring while improving responsiveness.
Reasonable next controls:
- Build a small grounding/confabulation eval set with representative public career-agent questions, fit memo prompts, and interview feedback transcripts.
- Track a simple AI quality metric: confirmed AI-content issues per 100 meaningful AI interactions.
- Track report-abuse categories: false fact, privacy issue, inappropriate content, prompt injection, impersonation, and other.
- Add a release checklist item for AI changes: AI instruction changed, model changed, provider changed, data flow changed, public disclosure changed, retention changed, evaluation run attached.
- Review voice transcription edge cases quarterly if voice usage increases.
Manage
NIST intent: Prioritize, respond to, reduce, transfer, monitor, or accept risks. Communicate incidents and errors. Deactivate or roll back systems when needed.
Current HireProxy controls:
- Incident response page defines AI content, prompt injection, cross-tenant data leakage, service disruption, and voice/practice data incident types.
- Candidate assistants can be unpublished or disabled at a tenant level.
- Platform-wide AI surfaces can be restricted by deployment changes or provider configuration.
- Candidate edits refresh downstream AI context used for future responses.
- Account deletion removes user data, cancels subscription where possible, and deletes the auth user.
- Public data retention explains deletion and retention boundaries.
Reasonable next controls:
- Use the incident register template for every confirmed AI quality incident.
- Define severity levels: - Sev 1: confirmed cross-tenant data exposure, security breach, or personal data exposure. - Sev 2: materially false AI statement likely to affect hiring, reputation, or user trust. - Sev 3: low-impact incorrect or poor-quality AI output. - Sev 4: harmless quality issue or documentation gap.
- Maintain standard response targets appropriate for a solopreneur: - Sev 1: contain immediately, notify affected users when confirmed, document root cause and corrective action. - Sev 2: investigate within one business day, correct content or AI instructions, and notify the affected candidate when appropriate. - Sev 3 and Sev 4: batch into weekly or quarterly quality review unless patterns emerge.
- Revisit risk posture before selling to enterprises, universities, outplacement firms, or other institutional customers.