Skip to content

Trust center

Security

Last updated: October 2026

This page describes how we protect data today, not plans. Where we are not yet where we want to be, we say so.

We keep less data to begin with

  • We do not record or store interview video or audio. Your camera preview never leaves your browser, and only the text of your answers reaches us.
  • We do not store resume files. If you choose one during sign-up, your browser reads it and we do not upload the file.
  • We do not ask for ID documents, selfies, or anything biometric.
  • We do not see or store full card numbers. Payments go through Stripe.

Where data is stored

Aethel runs on Google Cloud through Firebase. Our website is served by Firebase Hosting. Sign-in uses Firebase Authentication. Account, profile, and interview data is stored in Cloud Firestore in Google's United States multi-region location, and our server code runs on Cloud Functions in the United States.

Encryption

  • In transit: every page and every request to our servers uses HTTPS. Browsers are told to always use HTTPS for aethel.pro.
  • At rest: Google Cloud encrypts stored data by default. We rely on Google's default encryption and do not add a separate layer of our own.

Who can access what

  • Database rules decide who can read each record. Your stored transcript and results can be read directly only by you and by authorized Aethel staff.
  • A company can open your result only through our server, which checks that the company owns the interview link and that you started the interview from it.
  • No one can change a stored transcript or result from a browser, including our staff. Only our server code writes them, after it checks that the interview session is yours.
  • Each scored result is signed with a secret key when it is created, so later changes to it can be detected.
  • Staff access is limited to a small number of named accounts that need it to run the service, answer support requests, or investigate abuse.

Keys and passwords for our services

The key that signs interview results, our email sending credentials, and our error monitoring settings are stored in Google Secret Manager. The keys for our AI provider and our payment provider are still stored as server settings outside Secret Manager, and are being moved to it.

No secret keys are included in the website code that runs in your browser. The browser only receives keys that are meant to be public, such as the Firebase web settings.

Error monitoring

Our server code reports errors to Sentry so we can find and fix problems. Error reports contain technical details, such as which function failed and the error message.

Payments

Companies pay through Stripe Checkout, a payment page run by Stripe. Card details are entered on Stripe's page and never reach Aethel's servers. When Stripe tells our server about a payment, our server checks Stripe's signature on the message before acting on it.

Website protections

Our website sends standard security headers, including a content security policy that limits which scripts can run, and settings that stop other sites from showing our pages inside a frame.

What we have not done yet

  • We hold no security certification, such as SOC 2 or ISO 27001, and we do not claim to.
  • No independent security test (penetration test) has been done yet.
  • Aethel does not yet require two-step sign-in for staff accounts.
  • We do not yet keep a log of which staff member or company viewed which record.

If something goes wrong

No system is perfectly secure. If we learn of a breach that affects your data, we will tell you, as our privacy policy says.

Report a vulnerability

If you think you have found a security problem in Aethel, email support@aethel.pro with "Security" in the subject. Please include:

  • What you found and where (the page or address).
  • The steps to reproduce it.
  • What someone could do with it.

A person at Aethel replies within 2 business days. Please do not access, change, or delete other people's data while testing, and give us a chance to fix the problem before you share it publicly. We do not offer payment for reports today.