Security
Last updated: August 17, 2026
Security is central to AI Assessment because the Service processes sensitive candidate data — written, voice, and video responses. This page summarizes the safeguards we have in place and how to report an issue.
Infrastructure
The Service runs on established cloud infrastructure with network isolation, managed identities for service-to-service access, and regular patching of the underlying platform.
Encryption
- In transit: all traffic is served over TLS (HTTPS/WSS).
- At rest: stored data and uploaded media are encrypted at rest.
Access control
- Role-based access separates candidates, recruiters, and administrators.
- Access to production data is limited to authorized personnel on a need-to-know basis.
- Assessment links are time-boxed and scoped to a single candidate session.
Candidate data handling
Candidate responses are used to produce assessment results and are retained per the controlling organization’s configuration, then deleted or anonymized. See our Privacy Policy for details on collection, retention, and rights.
Sub-processors
We use vetted providers for hosting and AI processing under contractual security and data-protection commitments. A current sub-processor list is available on request.
Ongoing work
We continuously harden the Service and are maturing our formal security program and compliance posture. This page will be updated as those programs advance.
Reporting a vulnerability
If you believe you have found a security issue, please email security@aslase.com with details so we can investigate. We appreciate responsible disclosure and will not pursue good-faith research.