Authentication

  • OIDC Authorization Code Flow with PKCE in the system browser.
  • The desktop is a public client and holds no client secret.
  • Short-lived access tokens; refresh tokens stored with Windows DPAPI.
  • No credentials are collected inside the app.

Entitlements

  • Signed entitlement documents validated offline against a pinned public key.
  • Server-side authorization for every server operation.
  • Bounded offline grace; no indefinite offline premium access.
  • Clock-rollback and stale-version detection.

Billing

  • Hosted Checkout and Customer Portal; card data never touches AI Interview Assistant.
  • Webhook signatures verified over the raw body; durable, idempotent inbox.
  • Periodic reconciliation with the billing provider.

Data

  • TLS in transit; encryption at rest in the managed database.
  • Secrets in a managed secret store, never in source or deployment files.
  • No interview content stored in the cloud backend. Included Credits requests are relayed in memory to an approved external AI provider with AI Interview Assistant's server-side credential and are not stored or logged; only usage metadata is kept.
  • AI provider credentials for Included Credits live only in the managed secret store; BYOK keys stay in Windows Credential Manager on your computer.
  • Least privilege and audited admin actions.

Reporting a vulnerability

Report suspected vulnerabilities through the support channel. Do not include secrets or personal data.