Security
How Panelio is built
The app runs on Vercel; the data lives in one Postgres database and one private storage bucket on Supabase, in the United States (Ohio); a resume file is put into the bucket through a link that takes one upload to one path, and only the server reads it back; Panelio's seat in each live meeting, which hears the meeting's media stream for the transcript and speaks as the AI interviewer, runs in a Vercel Sandbox of its own for the length of the round; candidate code and the coding assistant's tests run in an isolated execution box with no network, capped at three seconds a run for most languages and thirty at most. Sign-in is Zoom OAuth with PKCE, and every request is checked against a signed session cookie. Every database query is scoped to the workspace of the session, and Row Level Security is on for every table with no public access.
Encryption
TLS on every connection. Encryption at rest by the database provider. Each workspace has a data key of its own, kept wrapped by a master key the database never holds; a workspace's resumes and their files, the transcript of its rounds, its evidence packs and its candidates' voiceprints are stored encrypted with that key (AES-256-GCM), bound to the workspace, so one workspace's key never opens another's. Deleting a workspace deletes its key, so what it held cannot be read again from the database, the storage bucket or any copy made of them; the database provider's own backups keep the wrapped key until they expire. The Zoom sign-in tokens Panelio keeps to read a member's meetings are encrypted with AES-256-GCM under a key derived from the app secret, decrypted on the server only for the length of a call, and never logged. Panelio's seat in a meeting is handed the key of its round's workspace alone, never the master key. Workspaces bring no model keys: every model runs on Panelio's account. Webhooks from Zoom are verified by HMAC before anything is read.
In the browser
The app sends a content security policy with a fresh nonce on every page, lets only Zoom's client frame it, and asks browsers for HTTPS only, no content sniffing, and no camera, microphone or location. Its cookies are secure and out of reach of the page's scripts. Cross-site requests cannot reach its data routes.
What is kept
Audio is transcribed as it arrives and not kept as audio. The transcript, the code timeline, the whiteboard, the coding assistant's record, notes, grades, the evidence pack and the resume with its file are kept for the workspace's retention period after the decision on the candidate, 90 days by default and at most one year, then erased; a resume and its file also go when its role is deleted for good, and its candidates are kept only as a number. Each decision stays as it was recorded, with the candidate as a number, for the employer's audit. A voiceprint goes at the hiring decision for its role, and never later than a year after the candidate's last round of it. Video is never recorded. Secrets live in the host's environment, never in the code, and a secret scan runs on every change.
Where the data is
In the United States: the database and the files in Ohio, the execution box in New Jersey, and every subprocessor processing in the United States, with requests passing through the hosting network's nearest edge.
Access
Roles inside a workspace: admin, hiring manager, interviewer, reviewer. A reviewer sees the candidates and upvotes them, nothing else. Removing a role for good, cancelling its Zoom meetings and linking it to a job in the applicant tracking system are an admin's or the role's owner's. Only admins change the settings and billing. A candidate reaches one editor or one prep page by an unguessable token and nothing else. Every decision is recorded with the person who made it, and the audit export lists them all with the quotes behind every grade.
Removing the app
When someone removes Panelio from their Zoom account, Zoom tells Panelio, which checks that the message is Zoom's, tells Zoom to revoke the sign-in it held for that person, and erases them at once in every workspace: their name, their email and their Zoom login are deleted, so nothing more is read from Zoom on their behalf. What they recorded stays on the employer's hiring record under "A former member". An admin can delete a whole workspace in Settings, Data; it goes 7 days later, with its key, unless an admin cancels. The documentation says what stays and how to ask for it to go.
Subprocessors
Vercel, Supabase, OpenAI, Resend, Vultr. Changes are emailed to workspace admins 30 days ahead.
| Subprocessor | What it does | Region | When |
|---|---|---|---|
| Vercel | hosts the app and the API, and Panelio's seat in each live meeting | United States and EU edge | always |
| Supabase | the database, stored resume files and realtime channels | United States (Ohio) | always |
| OpenAI | the model behind grading, the coach, the AI interviewer and the agent, on Panelio's account; no training on the data | United States | always |
| Resend | transactional email: invitations, the candidate's note, reviewer nudges | United States | when a workspace sends email |
| Vultr | the execution box that runs the candidate's code, in a container with no network; nothing is kept there after a run | United States (New Jersey) | when a round runs code |
If something goes wrong
If a security incident reaches an employer's data, Panelio tells the workspace's admins within 72 hours of confirming it, with what was reached and what was done, and helps them tell the people affected. When it touches data from Zoom, Panelio also tells Zoom within 24 hours, as Zoom's terms ask.
What is not in place yet
A third-party penetration test and a SOC 2 report are planned, not done; the Zoom Marketplace runs its own security review before the app is listed. Until then Panelio shares a trust packet on request: this page, the privacy policy, the technical design document from the Marketplace submission, and the current dependency audit.
Reporting
Write to support@panelio.ai with what you found and how to reproduce it. We do not pursue researchers who report in good faith and keep the data they reach to themselves.