AI features and what leaves the platform
AI in the Service assists a recruiter; it does not decide. Nothing is advanced or rejected automatically, and a human reviewer remains accountable for every hiring outcome. One external AI processing service supports every feature below, apart from the Senior Help handoff described under the help assistant, and processes request data outside Singapore. Each request is scoped to its enabled task; the service never receives a bulk export of your workspace.
Recruiting assistance
Job-description drafting sends the role details and the outcomes and qualifications a recruiter has approved, plus any organisation context or compensation text they choose to include. Interview-question generation sends the job title and its published rubric criteria, or the job's stored requirements where no rubric is published. Drafting an assignment rubric with the assistant sends the job title and description, the assignment brief and settings, and the recruiter's setup conversation; calibrating that rubric sends the sample answers your team supplies, with the brief and rubric but not the expected scores. None of these requests reads a candidate record, although sample answers are sent exactly as your team enters them. The earlier resume-scoring feature has been retired, and candidate comparison now reads saved Candidate Fit reviews (below) without sending a new request to the AI service.
Two features do send candidate content, and we will not let that paragraph imply otherwise. The first is CV extraction. When our own parser cannot find a candidate's name and email in a CV — or reads it but produces only a sparse profile — the extracted text is sent to the same service to recover the work history, skills, and education the parser missed. Before it leaves, email addresses, links, phone numbers, address and personal-details lines, referee sections, and any name the parser did find are masked, and contact details are recovered locally rather than by the model. That masking is pattern-based, not field-level redaction: a name the parser could not find, or an identifier written into the prose, can still go with the text. The sparse-profile trigger also means a CV the parser handled adequately can still be sent. File bytes never are; only text.
The second, and the most significant for candidates, is automated case-study assessment, which sends the most candidate-authored content of anything we do. When a candidate submits a take-home assignment, the text extracted from their file goes to the same service along with the assignment brief and the rubric criteria set for AI assessment, so it can be scored against that rubric. It runs only against a rubric your team has calibrated and approved, and it fires on submission rather than when a recruiter asks. Whatever the candidate chose to put in that document goes with it, and the resulting score is internal to your team — the candidate is not shown it, and it does not advance or reject anyone by itself.
Candidate Fit
Candidate Fit uses versioned organisation context, immutable job criteria, and minimised candidate evidence to produce a cited recommendation for recruiter review. It replaces the retired resume score. It cannot change an application score, stage, or status; reject or shortlist a candidate; schedule an interview; send a message; or create an offer. The capability is released, but production candidate processing is not currently activated. Optional organisation research is separately disabled by default.
Analytics dashboard chat
Create with chat sends your instructions, bounded conversation history, and dashboard definition to the same AI processing service, outside Singapore. It does not send the underlying report dataset, computed results, resumes, or automatically loaded candidate records. User-entered text and filter labels are not automatically redacted. The service proposes a validated configuration, not executable SQL or calculated figures. Reports are calculated separately under the viewer's database access permissions. The feature is limited to eligible administrator and recruiter accounts and respects workspace AI controls, feature allowlisting, quotas, and rate limits.
Saved dashboards retain the latest 30 chat messages and 10 definition revisions until the dashboard is deleted. Workspace sharing includes this conversation and definition history for permitted readers, but does not broaden their access to underlying records. Unsaved recovery drafts are tab-local and scoped to the signed-in account, workspace, and dashboard.
In-product help assistant
The in-product help assistant is available on every plan, including Free; the other AI features in this section are not part of Free. The assistant receives your message, recent help-chat history, the screen path you are on, your workspace name, your plan and role, and aggregate count-only figures — how many jobs or candidates exist and how many sit at each pipeline stage. It receives no individual candidate, job, application, or other person's record. That is enforced by the shape of the data structure it is given, whose fields are numbers and your own workspace name, and by count-only database queries that transfer no rows at all.
If a signed-in user chooses Ask Senior Help, the help conversation and the screen path are passed to a separate assisted support workflow that we operate, which may use a different external AI service, outside Singapore, to prepare a reply. The handoff grants no additional record access and performs no hiring action, and no human response or response time is promised. Escalated conversations are scheduled for deletion after 90 days.
Across external AI processing
- Untrusted text is fenced and escaped before it reaches a model, with instructions inside it explicitly disregarded, and model output is schema-validated before the product acts on it.
- Provider endpoints are pinned to an allowlist of hosts over HTTPS, so a misconfigured or tampered environment variable cannot redirect prompts elsewhere.
- Apart from help-assistant replies, AI requests carry a one-way hash of the workspace identifier for provider-side isolation. This pseudonymous tag does not identify individual candidates.
- We do not use customer or candidate data to train our own models, and we do not license that data for model training.
- Outside the Free plan, AI features can be switched off for a workspace, per feature or entirely. Ask us — this is currently an operator setting on our side, not a self-service toggle in your settings. On the Free plan, the in-product help assistant is part of the plan and cannot be switched off separately; it processes only what a signed-in user types into it, and Free includes no other AI features.