Security and Data Processing
Effective date: August 27, 2026 · Contact: [email protected] · For vulnerabilities, include “security” in the subject line.
This page describes how MockWise actually stores resumes, processes audio, and uses third-party services, based on the current Docker/Postgres/Redis/R2 deployment. We avoid unverifiable claims and link to source behavior.
Infrastructure
- App: Spring Boot (Java) on Docker (`mockwise-app`), Postgres 16 (`mockwise-db`), Redis 7 (`mockwise-redis`), Next.js frontend (`mockwise-frontend`). See
docker-compose.yml. - TLS: HTTPS via Cloudflare (edge) to the origin. We do not terminate TLS in-app; ensure `CORS_ALLOWED_ORIGINS` includes
https://mockwiseai.comandhttps://api.mockwiseai.com. - Auth: BCrypt password hashing, JWT (`accessToken`/`refreshToken`) with `exp` check in
src/proxy.ts; unauthenticated protected routes →307to/withX-Robots-Tag: noindex. - Secrets: not baked into images. `JWT_SECRET`, `GROQ_API_KEY`/`GEMINI_API_KEY`, `RAZORPAY_*`, `R2_*`, `MAIL_*` come from environment.
Resume storage
- Upload via
POST /resumes: validated to PDF/DOCX, max 10 MB, max 5 per user. - File is saved via
FileStorageServicetouploads/resumes/<userId>/<uuid>_filenameon local disk (LocalFileStorageService→uploads/Docker volume) or to Cloudflare R2 (R2FileStorageService→ bucketmockwise-files) whenS3Clientis configured. The DB storesfileUrl(the key) andparsedText. - Parsed text is extracted by
ResumeParserand sent asynchronously to Groq to extract skills/experience/education; failures are logged but do not block upload. - Delete via
DELETE /resumes/{id}callsfileStorageService.deleteFile(key)(localFiles.deleteIfExistsor R2DeleteObject) and deletes the DB row. Also available in UI at /resumes.
Audio processing
- Browser records via
MediaRecorder; chunks are accumulated in memory (AudioTranscriptionService.pendingChunks). - On final submission,
transcribe(interviewId, byte[], filename)checks size: <10 KB → empty transcript, >25 MB → rejected (“Recording is too long”), else posts to Groq Whisper (https://api.groq.com/openai/v1/audio/transcriptions, modelwhisper-large-v3-turbo) withBearer GROQ_API_KEY. - Audio is not persisted as a long-term file in Postgres/R2; it is held in memory for the transcription call and then the entry is removed (
pendingChunks.remove). Transcripts are stored as interview messages. - We do not share audio with other users; only the transcription provider receives the bytes for the duration of the API call.
AI and other third parties
- Groq:
https://api.groq.com/openai/v1/chat/completionsfor interview chat/report, with retry on 429 and semaphore limit 25. Models:openai/gpt-oss-120b(chat/report) andopenai/gpt-oss-20b(fast). Gemini is used for reports ifGEMINI_API_KEYset (gemini-2.5-flash). - Speechmatics/Kokoro: TTS for voice interviews if enabled (controlled by
KOKORO_ENABLED,SPEECHMATICS_API_KEY). - Razorpay: payments (order creation via
RazorpayService); card/UPI data goes to Razorpay, not us. - Email: SMTP via
smtp.gmail.comwhenMAIL_USERNAME/MAIL_PASSWORDset, from[email protected]. - Analytics/protection: Google Analytics (GA4) and Cloudflare bot/CDN if configured. No resume/transcript content is sent to analytics.
Retention and deletion
- Resumes: until you delete them or we delete your account.
- Interviews/reports: while account exists; account deletion removes your rows (subject to legal backup retention).
- Audio: not retained as files; only transcripts remain.
- To request export or deletion: Contact or [email protected]. We will verify ownership via email.
What we do not claim
- No SOC 2, ISO 27001, or HIPAA certification at this time.
- No at-rest encryption guarantee beyond what Postgres/Redis/R2 and your host provide; we rely on TLS in transit and platform controls.
- We do not review resumes for accuracy; parsing is best-effort.
Reporting issues
Email [email protected] with “security” in the subject. Include steps to reproduce, impact, and we will acknowledge within 3 business days. Do not publicly disclose until we have had a chance to fix.
Related: Privacy Policy · Terms · Contact