VPC-deployed AI hiring with zero customer production-data egress
VPC-deployed AI hiring runs inside the customer's approved cloud environment. The contained configuration described here uses local inference and customer-controlled data paths. Zero customer production-data egress requires the model, connectors, telemetry, support, and backup paths to preserve that boundary.
Nodes also supports Nodes Cloud and customer-managed on-premises deployment. Nodes Cloud has a separate Nodes-managed boundary. This page describes a private VPC design for review, rather than the behavior of every deployment. Nodes works within configured permissions. Actions requiring approval remain gated by the customer's policy.
What the VPC boundary includes
In the contained design, model operations, evidence storage, and authorized execution stay inside the approved customer VPC. The customer sets network policy, access, region, and retention. Verify those controls in the proposed application.
Local open-weight models can support this boundary when they meet the task requirements. Fine-tuning is an optional, separately evaluated mechanism; retaining company intelligence does not require retraining model weights. Customer-confidential memory is not pooled across tenants by default. Any permitted artifact release needs a defined review and approval process.
The production data path
The contained configuration admits only approved sources and excludes hosted foundation-model calls from the production path. A different configuration may permit an external endpoint, but that data movement must be explicit. A private deployment label alone is insufficient.
The proposed connector design uses scoped permissions and reviewable mappings with visible uncertainty. Test that a human verifies uncertain mappings and that a changed field stops affected work. Broad discovery and generated repair are product direction; establish actual operation coverage and retained engineering effort before acceptance.
The human gate and Decision Trace
Named people retain consequential decision authority. A person can question, edit, approve, delay, or decline a proposed action. Routine work can continue within standing authorization; a new objective cannot silently expand access or scope.
The intended Decision Trace links evidence, versions, human reasoning, authorized action, and later outcome. Inspect the record available in the contracted application. The broader autonomous runtime and automated learning loop are product direction, separate from the current insurance candidate-evaluation application. Designated workflows can require a second signer.
What the public deployment proves
The current production evidence comes from enterprise talent at one Fortune 500 insurance carrier. That deployment completed legal approval in 17 days and moved from contract to production in 34 days after six AI hiring vendors had been rejected over 18 months on architecture.
Those results explain why the boundary matters. They do not promise the same review or deployment timeline for another customer. Every new company and decision program starts with separate historical validation and its own security review.
What is available for review
- SOC 2 Type II report under NDA
- the deployment data-flow diagram
- connector permissions and proposed field mappings
- model ownership and exit terms
- Decision Trace and human-approval behavior
- the controls that stop uncertain mappings or weak evidence from moving forward
Frequently asked questions
What is VPC-deployed AI hiring? AI hiring software that runs inside the customer's virtual private cloud, with candidate data and model operations contained inside that approved boundary.
Does Nodes send candidate data to an external model provider? The contained local-inference configuration excludes that path. Other customer-approved configurations may use hosted models. Review the actual inference, connector, telemetry, and support routes before accepting a zero-egress claim.
Who owns the model weights? Customer-specific weights, where present, and separable company intelligence remain governed by the agreement. Request sample exports with identifiers, schemas, relationships, and provenance. Confirm what remains usable after the licensed runtime and service end.
Does Nodes make the final hiring decision? No. A named person retains the hiring decision. Routine coordination follows configured permissions; consequential decisions and actions requiring approval remain gated by customer policy.
Review the boundary for one decision
Bring one repeated hiring decision, the systems it crosses, and the security constraints that govern it. Nodes will map the data path, evidence requirements, human gate, and stop conditions before a production scope is proposed.