Product security overview
Understand the access, isolation, link, storage, and activity safeguards visible in the Probb AI product.
Organisation isolation and access
Authenticated records are scoped to the active customer organisation. Viewer, Member, and Admin roles control organisation access, while write procedures reject Viewer mutations. Admin-only operations include workspace profile, team, invitation, role, usage, and activity management.
Users should confirm the active organisation before uploading, downloading, sharing, or deleting candidate information.
Files and storage access
Uploaded resumes and interview recordings are kept in object storage. Upload and download operations use short-lived signed URLs. A signed file URL should still be treated as confidential while it remains valid.
Original resume downloads and exported PDFs leave the controlled workspace. Customers are responsible for securing, retaining, and deleting those copies.
Public report links
Public reports use long unlisted bearer links and field-level visibility controls. They do not require recipient authentication and do not currently expire automatically. Anyone who possesses an active link can access its enabled content.
The report creator or an organisation Admin can change visibility, replace the link token, or revoke the link. Original resume files, interview audio, and debug data are never included in the public report.
Interview invitations
Interview links are checked against session status and expiration. Invitations normally expire after seven days and should be sent only to the intended candidate.
Password and session protections
Users can change their password from account settings and request password recovery from the sign-in flow. Do not share accounts or invitation links. Sign out on shared devices and report suspected unauthorised access through the customer's approved support channel.
Activity records
Probb AI records selected organisation events for administrative review, including relevant membership, usage, report, interview, sharing, and settings activity. The activity view is operational history, not a guaranteed immutable or exhaustive compliance audit log.
Reporting a security concern
Use the security or support contact provided by your Probb AI agreement. Do not include unnecessary candidate records, transcripts, passwords, access tokens, or active public links in an initial report.