Public AI Governance Documentation
AI Governance Package
Scope, source frameworks, current controls, publication boundaries, and review notes.
Last reviewed: July 9, 2026
This package documents how HireProxy manages AI risk in a way that aligns with the NIST AI Risk Management Framework (AI RMF) 1.0 and the NIST AI 600-1 Generative AI Profile. It is written for public publication and intentionally omits application source code, secrets, raw prompts, internal credentials, and tenant data.
This is not a certification, audit report, or legal compliance claim. NIST AI RMF is a voluntary risk management framework. NIST states that AI RMF 1.0 is currently being revised, so this package should be reviewed when NIST publishes material updates.
Publication Boundary
This public package is intentionally a governance summary, not an implementation manual. It does not publish raw prompt text, exact evaluation cases, incident details, internal checklists, source code, database schema, tenant data, operational runbooks, or provider-console settings.
Internal supporting artifacts should stay outside any public documentation repo.
Scope
HireProxy is a multi-tenant SaaS platform operated by Broadlake Technologies LLC. It uses AI to help candidates:
- Build and maintain a candidate-owned AI career website.
- Answer recruiter questions using candidate-provided career evidence.
- Analyze role fit against job descriptions.
- Generate job-specific interview prep.
- Practice interview answers with voice transcription, spoken coaching, scored feedback, adaptive follow-up questions, and private story refinement.
HireProxy is not an employer screening, ranking, rejection, credit, housing, education, insurance, medical, law enforcement, or government-benefits system. It does not make hiring decisions and should not be used as the sole basis for hiring decisions.
Source Frameworks
- NIST AI Risk Management Framework 1.0: https://www.nist.gov/itl/ai-risk-management-framework
- NIST AI RMF Core and AIRC implementation resource: https://airc.nist.gov/airmf-resources/airmf/5-sec-core/
- NIST AI 600-1, Generative AI Profile: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
- NIST AI 600-1 PDF: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
Package Contents
- system-cards.md - Public system cards for the main HireProxy AI surfaces.
- nist-ai-rmf-alignment.md - Govern, Map, Measure, and Manage alignment.
- genai-profile-risk-map.md - Mapping to the NIST AI 600-1 GenAI risk categories.
- evaluation-monitoring.md - Practical evaluation, monitoring, and release cadence for a solo-founder SaaS.
- vendor-and-model-register.md - Public provider, model-use, and data-flow register.
- incident-register-template.md - Lightweight incident register template.
- changelog.md - AI governance documentation change log.
Current Control Summary
HireProxy already has meaningful controls in place:
- Public privacy, data retention, AI risk assessment, incident response, and terms pages.
- Candidate-facing disclosures that AI can make mistakes and that final facts should be confirmed with the candidate.
- Terms prohibiting fabricated credentials and undisclosed live-interview assistance.
- Candidate control over public career-site content and private interview practice data.
- Prompt guardrails for no new facts, story-first evidence, uncertainty fallback, employer/client separation, high-risk fact caution, and employment history accuracy.
- Tenant-scoped data storage with Supabase Row Level Security on sensitive user-owned tables.
- Rate limits, entitlement checks, usage caps, input length limits, and abuse reporting.
- Error and provider-failure monitoring through Sentry.
- Privacy-constrained session diagnostics limited to non-sensitive marketing surfaces when enabled.
- Voice practice audio is processed for transcription and spoken coaching, but saved practice records store transcript, metrics, and feedback rather than a saved practice audio file.
- Interview Mode keeps quick spoken coaching concise and scoreless, with the full written rubric as the scoring source of truth.
Highest-Priority Next Steps
These are the reasonable next controls for a solopreneur trying to align closely with NIST AI RMF without creating enterprise theater:
- Keep the public AI governance page and linked public documentation current, with no source code, raw prompts, secrets, tenant data, or internal runbooks.
- Maintain the internal incident register for AI quality, privacy, security, provider, and voice-practice incidents; keep the public template generic.
- Add a small grounding/confabulation evaluation set and run it before major prompt changes, model upgrades, or launch campaigns.
- Keep the vendor/model register and AI governance changelog current.
- Perform a quarterly AI risk review using the scheduled operator review and the checklist in evaluation-monitoring.md.
- Add internal vendor review notes for Anthropic, OpenAI, Supabase, Vercel, Resend, LemonSqueezy, Sentry, LogRocket, and Cloudflare Turnstile before enterprise or outplacement sales.
Publication Notes
Before publishing:
- Remove any internal-only comments added during review.
- Do not include source code snippets, prompt text, API keys, database schema dumps, customer data, screenshots containing tenant data, or private logs.
- Do not publish the internal incident register, internal eval set, provider settings checklist, or public/private boundary review.
- Use "aligned with" or "mapped to" NIST AI RMF. Avoid language that implies NIST certification, NIST approval, formal NIST compliance, or external audit.
- Keep the date visible and review after NIST publishes an AI RMF revision.