Security overview
How AI Interview Assistant protects accounts, subscriptions and data.
Authentication
- OIDC Authorization Code Flow with PKCE in the system browser.
- The desktop is a public client and holds no client secret.
- Short-lived access tokens; refresh tokens stored with Windows DPAPI.
- No credentials are collected inside the app.
Entitlements
- Signed entitlement documents validated offline against a pinned public key.
- Server-side authorization for every server operation.
- Bounded offline grace; no indefinite offline premium access.
- Clock-rollback and stale-version detection.
Billing
- Hosted Checkout and Customer Portal; card data never touches AI Interview Assistant.
- Webhook signatures verified over the raw body; durable, idempotent inbox.
- Periodic reconciliation with the billing provider.
Data
- TLS in transit; encryption at rest in the managed database.
- Secrets in a managed secret store, never in source or deployment files.
- No interview content stored in the cloud backend. Included Credits requests are relayed in memory to an approved external AI provider with AI Interview Assistant's server-side credential and are not stored or logged; only usage metadata is kept.
- AI provider credentials for Included Credits live only in the managed secret store; BYOK keys stay in Windows Credential Manager on your computer.
- Least privilege and audited admin actions.
Reporting a vulnerability
Report suspected vulnerabilities through the support channel. Do not include secrets or personal data.