TwinEthos homeRequest access

Control

Applicant interview videos shared beyond the people and services that evaluate the applicant

Recorded applicant interview videos reach only the people and services whose expertise or technology is needed to evaluate the applicant (the hiring team and the AI analysis vendor), never public links, marketing, analytics, model-training datasets or other recipients.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Control id cond.applicant-video-shared-beyond-evaluators

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in Illinois (US-IL).

Trust and provenance

How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.

This control
Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
Lanes
Binding law — not yet in force or stayed 1
Verification
Sources last verified 2 Oct 2026; each provision states how.
Data release
Data release 2026.10.03, data as of 2 Oct 2026, schema 0.3.9.
Legal review
None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

The guard to add

Keep interview videos in private storage and share them only with recipients on an evaluator allowlist (hiring team, AI analysis vendor), through short-lived links issued after that check.

Interview videos live in a private bucket or container (block public access; no public-read ACL; no 'anyone' link permission). Every path that shares a video (a signed URL, an email or ATS attachment, a vendor upload, an export) goes through one function that checks the recipient against an allowlist of evaluator roles and the contracted analysis vendor, issues a short-lived link, and logs who received which video. Videos are excluded from analytics events, marketing tools and any dataset used to train or evaluate models for other purposes.

Where it goes: 1 application source code, 4 infrastructure-as-code, 6 API calls and integrations, 12 repository artifacts.

What reviewers look for: interview-video storage with public access blocked (no ACL='public-read', make_public(), allUsers, or 'anyone' link permission); a share_video/issue_link style function that checks an evaluator allowlist before generate_presigned_url or an upload to a vendor; no interview video in analytics, marketing or push_to_hub calls.

Example (Python + boto3 (S3)), before:

s3.upload_file(path, 'interviews', key, ExtraArgs={'ACL': 'public-read'})
share_url = f'https://interviews.s3.amazonaws.com/{key}'
notify_team(job.slack_channel, share_url)

After:

s3.upload_file(path, 'interviews', key)                      # bucket blocks public access

def share_interview_video(key, recipient):
    if recipient.role not in EVALUATOR_ROLES and recipient.id != ANALYSIS_VENDOR_ID:
        raise PermissionError('not an evaluator of this applicant')
    url = s3.generate_presigned_url('get_object', Params={'Bucket': 'interviews', 'Key': key}, ExpiresIn=900)
    share_log.record(key=key, recipient=recipient.id)
    return url

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — not yet in force or stayed (1)

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.