Security approach
Boundaries that support careful review.
Honesti separates candidate-agent access from recruiter access and limits each organization to its own workspace data.
Organization-scoped access
Recruiter requests are authenticated and scoped to the user’s organization. Agent credentials are separate from recruiter sessions and are limited to the assigned interview session and permitted write operations.
Credential handling
Passwords are stored as password hashes. Candidate setup tokens, pairing codes, invitation tokens, and Greenhouse API credentials are stored as hashes rather than their original values. Pairing and setup credentials are designed for a specific workflow rather than general workspace access.
Auditability
Honesti records organization audit events for sensitive actions such as viewing, exporting, reviewing, and deleting session information. This helps administrators understand who interacted with a record.
Data lifecycle controls
Organizations can configure retention, export session records, and delete session data. The retention process removes eligible sessions and related events, preflight information, reports, and agent records after the organization’s configured window.
Product boundaries
Honesti does not claim that integrity signals prove misconduct, and it cannot observe activity on a separate phone or computer. It is designed to provide evidence for human review, not a certainty score or automated verdict.
Security questions
For deployment or security-review questions, contact founders@honesti.ai. You can also read our privacy overview and frequently asked questions.