Why IdealResume Could Never Have a Mercor-Style Data Breach
What Happened at Mercor
On March 31, 2026, hackers claimed they stole 4 terabytes of data from Mercor, a $10 billion AI hiring platform. The breach reportedly includes:
- **211 GB of candidate resumes** and personal information
- **Terabytes of recorded video interviews** — faces, voices, mannerisms
- **Passport and KYC documents** — government-issued IDs uploaded for verification
- **Nearly 1 TB of source code** — the platform itself
If you ever applied for a job through Mercor, your face, your voice, your government ID, and your resume may now be available on the dark web.
This is not a hypothetical. This is today.
---
The Real Problem Is Not the Hack — It Is the Architecture
Mercor stored everything. Permanently. Centrally. Video interviews recorded and kept forever. Passport scans sitting in a database. Resumes with home addresses, phone numbers, and employment history in one place.
When you build a system that collects everything and deletes nothing, you are not building a product. You are building a target.
A breach of this scale is not fundamentally a firewall failure or a VPN misconfiguration. It is a lapse in proper data governance — the absence of deliberate decisions about what to collect, how long to keep it, and who can access it. Without that governance layer, every security tool in the world is just a lock on a door that opens into a warehouse full of dynamite.
The question is not "will it get breached?" The question is "when."
---
How IdealResume Is Built Differently
We do not store what we do not need. That is not a policy — it is the architecture.
1. No Video Recordings. Period.
IdealResume helps you prepare for interviews. We do not record them. There are no terabytes of your face and voice sitting on a server waiting to be stolen.
If a recording does not exist, it cannot leak. Simple.
2. No Passport Scans. No KYC Document Storage.
We do not ask for your government ID. We do not store passport photos. We do not retain biometric data.
Identity verification, when needed, happens through established third-party providers who specialize in secure identity verification. We receive a verification token — a simple "yes, this person is verified" — not the document itself.
Your passport never touches our servers. There is nothing to steal.
3. Resume Processing Without Permanent Storage
When you upload a resume to IdealResume, we extract the structured information we need — skills, experience, education — to help you improve it. The original file is processed and the raw document is not retained indefinitely.
If someone breached our systems, they would find structured career data. Not PDFs with your home address, social security references, and personal details embedded in metadata.
4. Encryption at Every Layer
IdealResume is built on PayEz Technologies infrastructure — the same infrastructure that powers PCI-compliant payment processing. This is not a startup that bolted on security after launch. The encryption layer was there before the first line of application code.
- **Data encrypted in transit** — TLS everywhere, no exceptions
- **Data encrypted at rest** — governed key lifecycle with hardware-backed key management
- **Application-layer encryption** — sensitive fields encrypted before they reach the database
- **CryptAply key governance** — encryption keys are managed through a dedicated governance layer with HSM-backed rotation, audit trails, and access controls. The keys that protect your data have their own lifecycle — they are created, rotated, and retired under policy, not left sitting in a config file for years
5. Minimal Data, Maximum Value
The Mercor breach leaked 4 TB. Four terabytes of data about job candidates.
Ask yourself: why does a job matching platform need 4 TB of data about you?
At IdealResume, we optimize your resume and help you prepare for interviews. That requires your career history and the job description. It does not require your face, your voice, your passport, or a permanent video library of your interview performance.
We collect what we need. We use it. We move on.
---
The Principle: Data You Never Had Cannot Leak
This is not a new idea. It is the oldest security principle in the book. The safest data is data you never collected.
Every piece of personal information a company stores is a liability. Every database is a potential headline. Every "we might need this someday" is a future breach waiting to happen.
The companies that survive the next decade of data breaches will not be the ones with the best firewalls. They will be the ones that collected the least and deleted the most.
---
What You Should Ask Every AI Platform
Before you upload your resume, record a video interview, or hand over your passport to any AI platform, ask:
- **Do they store my raw documents, or just the extracted data?**
- **Do they record and retain video interviews?**
- **Do they require government ID, and if so, where is it stored?**
- **What is their data retention policy? Do they delete, or keep forever?**
- **Is the data encrypted at rest, or just in transit?**
If the answer to any of these is "we keep everything" — you are trusting them with your digital identity. And as Mercor just proved, that trust can evaporate in a single afternoon.
---
Our Commitment
IdealResume exists to help you land your next job. Not to build a surveillance archive of your career.
- We do not record your interviews
- We do not store your government ID
- We do not retain what we do not need
- We encrypt what we do keep
- We are built on payment-grade security infrastructure
Your resume is your story. It should help you get hired — not end up on the dark web.
---
*IdealResume is built on PayEz Technologies — open source auth, database, and encryption infrastructure extracted from a PCI-compliant payment platform. Learn more at [PayEz.Net on GitHub](https://github.com/PayEz-Net).*
Ready to Build Your Perfect Resume?
Let IdealResume help you create ATS-optimized, tailored resumes that get results.
Get Started Free