HomeBlogAI in hiring

Six things to demand from an AI hiring vendor before you sign

A contract page with six questions written in the margin

Every demo shows you the same thing: a pile of CVs going in and a ranked list coming out. None of them cover what happens to the data afterwards, what you can take with you, or what the software does on the day you exceed your plan. Here are six questions that decide whether you will regret the contract, and our own answers to all six — including the ones that do not flatter us.

A separate question — can it reject someone without a human — deserves its own article and has one. Assume you have asked that first.

1. Where does candidate data live, and for how long?

Ask for the retention period in writing, per type of data. Not "we take security seriously". A number of days, for each thing they hold.

A good answer distinguishes between kinds of data, because they genuinely differ: a CV file, a parsed profile, an interview transcript, and an email you sent are four different things with four defensible answers. A bad answer is a single sentence about encryption, which is not what you asked.

Ours: interview transcripts, written answers, email bodies and launched interview links are deleted 12 months after they are created, enforced by the database rather than by a script somebody has to remember to run. CV files uploaded through a public application expire after 30 days. Proctoring snapshots, where they exist, also 30 days. Unverified signups are gone in 24 hours.

The unflattering part: the screening record itself — the score, the parsed profile, the gaps we found — has no expiry, and CVs uploaded by you in a batch are stored on that record rather than in the 30-day bucket. So a batch-uploaded CV persists until someone deletes the candidate. We think that is defensible, because it is your working record of your own hiring. It is also not what "CVs expire after 30 days" would lead you to assume, which is why we are spelling it out rather than letting you infer it.

2. Can you get your data out, and in what format?

Ask them to export your account in front of you. Not a promise; a file. The answer determines whether you are a customer or a hostage.

Watch for two evasions: "you can print to PDF" is not an export, and "contact support and we'll arrange it" means there is no export, only a favour that depends on the relationship being good — precisely the condition that fails when you want to leave.

Ours, honestly: you can export candidate lists and pipeline data as CSV from the dashboard yourself, at any time, including the email addresses. There is no one-click export of an entire account today. If you want everything, you email us and a person does it. That is a favour, not a feature, and we would rather say so than let you find out at the worst moment. It is on the list.

3. Can one candidate be deleted completely — and what survives?

The second half of that question is the one that matters. "Yes we can delete them" often means a row is hidden from the interface while the transcript, the emails and the CV sit where they were.

Ask: after deletion, what still exists, and why? There is usually a legitimate answer involving anti-fraud or billing records. You want to hear it stated, not discover it.

Ours: deleting a candidate removes the screening, the application, the CV file, the parsed profile, the interview session and transcript, the written answers, any proctoring snapshots, the email history and anything queued to send. What survives is a single anonymised marker carrying no personal data, so that the same person re-applying is not treated as a brand-new record forever. Only a workspace owner can do it, it cannot be done across workspaces, and it is irreversible. We have an automated test that fails the build if any of those collections is left behind.

4. What happens when you hit a limit?

This is the question nobody asks and everybody should, because there are three possible answers and two of them are unacceptable.

Ours: the third. At a plan limit, applicants keep their place and wait until there is room. They are never told a limit exists, because that is your commercial arrangement and not their business. The server capacity behind that has been measured rather than assumed.

5. How is it priced, and what exactly is metered?

Ask what counts as one billable unit, and then ask what does not. Vagueness here is always in the vendor's favour.

Specifically: does a candidate who applies but is never scored cost you anything? Does re-scoring after you edit the job description count twice? Does an abandoned interview count?

Ours: the monthly limit is CVs actually scored. Applications themselves are not metered — someone applying costs you nothing until you choose to score them. Your usage page shows what each stage cost at the published rates, as an estimate for transparency rather than an invoice, and the rates are visible to you rather than buried.

6. Who on the vendor's side can see your candidates and your costs?

Every multi-tenant product has staff who can technically see customer data. The question is whether they have thought about it and can describe the boundary.

Ask: can your support team read my candidates' CVs? Can another customer's admin ever see mine? What stops that?

Ours: every query is fenced to the workspace at the data layer rather than per-endpoint, so a forgotten check cannot leak across workspaces, and we have a test suite that tries to cross the boundary on every deploy and fails the release if it succeeds. Our own running costs are visible only to us and never to a client; what you see is your own usage at the published rates. Yes, our staff can access production data in order to operate it — anyone who tells you otherwise is describing a product nobody maintains.

How to use these six

Send them before the demo. The reply tells you more than the demo will: a vendor who answers all six in writing with numbers is a different proposition from one who answers with adjectives, and you will learn which you are dealing with before you have spent an hour watching a ranked list appear.

Then ask the seventh, which is really the first: can your software move a candidate to rejected without a human clicking? If the answer is yes, none of the other six matter.

Questions we get asked

What should I ask an AI recruiting vendor?

Where candidate data lives and for how long, whether you can export it, whether one candidate can be deleted completely, what happens at a plan limit, what exactly is metered, and who on the vendor's side can see your candidates.

How long should a hiring vendor keep candidate data?

Ask for a number in writing, per type of data. Ours: transcripts, written answers and email bodies are deleted after 12 months; CV files from public applications after 30 days.

If you want to see this on your own roles, request a demo — we set up a live job with your job description and show you the shortlist. You can also read our retention policy.