Security and Data Processing

Effective date: August 27, 2026 · Contact: [email protected] · For vulnerabilities, include “security” in the subject line.

This page describes how MockWise actually stores resumes, processes audio, and uses third-party services, based on the current Docker/Postgres/Redis/R2 deployment. We avoid unverifiable claims and link to source behavior.

Infrastructure

  • App: Spring Boot (Java) on Docker (`mockwise-app`), Postgres 16 (`mockwise-db`), Redis 7 (`mockwise-redis`), Next.js frontend (`mockwise-frontend`). See docker-compose.yml.
  • TLS: HTTPS via Cloudflare (edge) to the origin. We do not terminate TLS in-app; ensure `CORS_ALLOWED_ORIGINS` includes https://mockwiseai.com and https://api.mockwiseai.com.
  • Auth: BCrypt password hashing, JWT (`accessToken`/`refreshToken`) with `exp` check in src/proxy.ts; unauthenticated protected routes → 307 to / with X-Robots-Tag: noindex.
  • Secrets: not baked into images. `JWT_SECRET`, `GROQ_API_KEY`/`GEMINI_API_KEY`, `RAZORPAY_*`, `R2_*`, `MAIL_*` come from environment.

Resume storage

  • Upload via POST /resumes: validated to PDF/DOCX, max 10 MB, max 5 per user.
  • File is saved via FileStorageService to uploads/resumes/<userId>/<uuid>_filename on local disk (LocalFileStorageService → uploads/ Docker volume) or to Cloudflare R2 (R2FileStorageService → bucket mockwise-files) when S3Client is configured. The DB stores fileUrl (the key) and parsedText.
  • Parsed text is extracted by ResumeParser and sent asynchronously to Groq to extract skills/experience/education; failures are logged but do not block upload.
  • Delete via DELETE /resumes/{id} calls fileStorageService.deleteFile(key) (local Files.deleteIfExists or R2 DeleteObject) and deletes the DB row. Also available in UI at /resumes.

Audio processing

  • Browser records via MediaRecorder; chunks are accumulated in memory (AudioTranscriptionService.pendingChunks).
  • On final submission, transcribe(interviewId, byte[], filename) checks size: <10 KB → empty transcript, >25 MB → rejected (“Recording is too long”), else posts to Groq Whisper (https://api.groq.com/openai/v1/audio/transcriptions, model whisper-large-v3-turbo) with Bearer GROQ_API_KEY.
  • Audio is not persisted as a long-term file in Postgres/R2; it is held in memory for the transcription call and then the entry is removed (pendingChunks.remove). Transcripts are stored as interview messages.
  • We do not share audio with other users; only the transcription provider receives the bytes for the duration of the API call.

AI and other third parties

  • Groq: https://api.groq.com/openai/v1/chat/completions for interview chat/report, with retry on 429 and semaphore limit 25. Models: openai/gpt-oss-120b (chat/report) and openai/gpt-oss-20b (fast). Gemini is used for reports if GEMINI_API_KEY set (gemini-2.5-flash).
  • Speechmatics/Kokoro: TTS for voice interviews if enabled (controlled by KOKORO_ENABLED, SPEECHMATICS_API_KEY).
  • Razorpay: payments (order creation via RazorpayService); card/UPI data goes to Razorpay, not us.
  • Email: SMTP via smtp.gmail.com when MAIL_USERNAME/MAIL_PASSWORD set, from [email protected].
  • Analytics/protection: Google Analytics (GA4) and Cloudflare bot/CDN if configured. No resume/transcript content is sent to analytics.

Retention and deletion

  • Resumes: until you delete them or we delete your account.
  • Interviews/reports: while account exists; account deletion removes your rows (subject to legal backup retention).
  • Audio: not retained as files; only transcripts remain.
  • To request export or deletion: Contact or [email protected]. We will verify ownership via email.

What we do not claim

  • No SOC 2, ISO 27001, or HIPAA certification at this time.
  • No at-rest encryption guarantee beyond what Postgres/Redis/R2 and your host provide; we rely on TLS in transit and platform controls.
  • We do not review resumes for accuracy; parsing is best-effort.

Reporting issues

Email [email protected] with “security” in the subject. Include steps to reproduce, impact, and we will acknowledge within 3 business days. Do not publicly disclose until we have had a chance to fix.

Related: Privacy Policy · Terms · Contact