Trust center

Security at BuildInterview

BuildInterview separates customer authority, candidate execution, confidential assessment content, and recorded evidence so one capability does not grant access to another.

Effective 24 August 2026

Access and tenant isolation

  • Company users authenticate through a dedicated BuildInterview identity project.
  • Organization membership and role checks are enforced by the database and server, not browser state.
  • Candidate invitation secrets are exchanged once and are stored as hashes.
  • Administrative activation and service operations use separate, audited privileges.

Assessment and execution isolation

  • Confidential source, candidate packages, hidden graders, evidence, and recordings use separate private storage boundaries.
  • A candidate runtime receives only the package and tables locked to that question.
  • Hidden tests and reference solutions run in a separate grader environment.
  • Candidate code has bounded time, memory, output, and network access, with server-authoritative cleanup and metering.

Encryption and service identities

Production data is encrypted in transit and at rest. Private evidence storage uses customer-managed AWS encryption keys. Application and worker access uses scoped service identities and short-lived credentials where the provider supports them. Provider secrets are server-only and are never sent to a candidate browser or sandbox.

Secure development and response

  • Release builds run dependency, secret, private-path, type, contract, and production-trace checks.
  • Critical changes require exact release fingerprints and evidence receipts.
  • Security logs avoid candidate content and secrets, and object access is audited.
  • Confirmed incidents follow containment, evidence preservation, recovery, customer communication, and post-incident review procedures.

BuildInterview does not claim a security certification or independent audit unless the corresponding current report is provided to the customer.

Report a security issue

Send a clear description, affected URL, reproduction steps, and impact to the contact below. Do not access another person's data, disrupt an active interview, or publish confidential assessment material while testing or reporting a concern.

Questions about these terms or notices can be sent to hello@buildinterview.com. Candidates should also use the accommodation or appeal contact provided by the hiring company in their invitation.