Security & Retention
Short-lived CV artifacts with workspace-scoped access.
CVLens combines hashed API credentials, encrypted parser payloads, bounded document processing, and scheduled retention for sensitive candidate documents.
Workspace-scoped authentication
API tokens belong to a workspace and require the cv:parse ability for parser requests. Token secrets are shown once and stored only as hashes, while authenticated application access remains scoped to the current workspace.
Encrypted short-term retention
Uploaded CV files, extracted text, structured parse results, and optional analysis can contain personal data. Parser artifacts are stored encrypted and currently expire after seven days. The scheduled retention process deletes raw documents and clears parsed payloads after expiry.
Subprocessors and responsible use
CVLens sends extracted CV text and structured parser payloads to OpenAI for structured output and optional analysis. Where billing is enabled, Mollie processes payments, Lexware Office creates official invoices, and AhaSend delivers generic invoice notifications. These billing providers do not receive CV files, filenames, cache keys, or parser payloads.
Nightwatch supports operational monitoring with billing payloads, provider URLs, and sensitive provider errors redacted or excluded. Infrastructure, logging, security, and storage providers process only the operational data needed to run the service.
Customers remain responsible for a lawful basis to process candidate documents and for validating automated output before it affects hiring or other material decisions.
Try CVLens with your product workflow.
CVLens is currently available through private beta invitations.
Request Access