Public AI Governance Documentation

Vendor and Model Register

Public provider, model-use, data-flow, and review-trigger register.

This document is a public governance summary. It does not publish raw AI instructions, exact internal eval cases, source code, tenant data, incident details, database schema, or provider-console settings.

Last reviewed: July 6, 2026

This register describes HireProxy's AI and platform providers at a public, publishable level. It is not a substitute for private vendor due diligence, contracts, data processing addenda, or security questionnaires.

AI Providers

ProviderPurposeData categories processedCurrent risk controlsReview trigger
AnthropicCareer-agent responses, fit analysis, interview prep, answer evaluation, coaching, extraction, and structured generationCandidate-provided profile data, stories, work history, job descriptions, recruiter questions, prep context, answer transcripts, and generated outputsScoped request design, output limits, reliability monitoring, no custom model training by HireProxyModel upgrade, provider policy change, enterprise sale, material AI-instruction or data-flow change
OpenAIVoice transcription and text-to-speech for Interview ModePractice audio submitted for transcription, transcript text for spoken coaching, generated coaching scriptsAuthenticated endpoints, entitlement checks, rate limits, input size limits, no saved practice audio file in HireProxy records by defaultSpeech or transcription model change, voice retention change, enterprise sale

Infrastructure and Application Providers

ProviderPurposeData categories processedCurrent risk controlsReview trigger
SupabasePostgreSQL database, Auth, StorageAccount data, career data, resumes, interview prep, practice transcripts, usage events, settings, storage filesSupabase Auth, Row Level Security, server-side service-role access, storage path scopingNew table, new public data surface, RLS policy change, enterprise sale
VercelHosting and serverless runtimeHTTP requests, deployment artifacts, runtime logs, environment variablesServer-side secrets, runtime boundaries, deployment rollback capabilityRuntime change, sensitive surface change, enterprise sale
Vercel KVRate limiting and ephemeral countersIP-derived or user-derived rate-limit keys and request countersTTL-based expiry, scoped keysRate-limit architecture change
ResendTransactional email and abuse-report deliveryEmail addresses, transactional email metadata, abuse reportsTransactional-only use, limited report payloadsEmail flow change, abuse intake change
LemonSqueezyMerchant of record and subscription billingBilling customer IDs, subscription status, payment processor recordsHireProxy does not store full card numbersPricing, billing, or subscription architecture change
SentryError monitoring and provider-failure observabilityApplication errors, stack traces, request metadata, application context tagsNo raw user-facing error exposure, scoped error context, provider-failure metadataMonitoring configuration change
LogRocketProduct diagnostics on non-sensitive marketing surfaces when enabledMarketing-page interaction data, with text/body/input sanitization and blocked sensitive pathsDisabled on admin, candidate, start, upload, auth, interview, rehearsal, and sensitive API surfaces; IP capture disabledTelemetry scope change
Cloudflare TurnstileBot prevention on public start flowsBot-prevention challenge signalsRequired before public-start uploads or AI preparation continuePublic start flow change

Public Model-Use Principles