Trust Center

The facts your security and procurement teams need.

Review current controls, data practices, subprocessors, retention, and buyer documentation in one place. Every statement reflects the platform’s present posture.

Need a review package?

Request the DPA, submit a questionnaire, or tell us about a contractual requirement.

Start a security review

Current control summary

A concise buyer view with links to the full policies.

Encryption

TLS protects data in transit. Resume files use AES-256 server-side encryption in Amazon S3.

Access control

Supabase Auth, optional MFA, row-level database security, and short-lived file URLs restrict access.

Data boundaries

Individual career data remains private. Organization reporting uses program administration and aggregate insights.

Data rights

Customers can access, correct, export, and delete account data through the product or a privacy request.

Retention

Account data is removed within 30 days after deletion, except records retained for legal or financial obligations.

Operations

Rate limiting, signed payment webhooks, error monitoring, health checks, and controlled production deployments protect service operation.

Procurement documents

A direct review path.

Documents are provided for the proposed engagement so the parties, processing scope, and commercial terms are accurate.

  1. 1Submit your organization, program, participant volume, and required documents.
  2. 2We confirm the processing scope and answer the security questionnaire.
  3. 3The DPA and any agreed contractual terms are prepared for review.
  4. 4Approved documents are returned to the buyer contact for execution.

Subprocessors

Services that help deliver the platform.

ProviderPurposeProcessing location
Amazon Web ServicesEncrypted resume file storageUnited States
SupabaseDatabase and authenticationUnited States
AnthropicAI analysis and optimizationUnited States
OpenAIEmbeddings for semantic matchingUnited States
StripePayment processingUnited States
VercelWeb application hostingUnited States
RailwayAPI hostingUnited States
ResendTransactional email deliveryUnited States
CloudflareDNS, CDN, and email routingGlobal edge network
PostHogProduct analyticsUnited States
HeyCatchCookieless product analyticsUnited States
SentryError monitoringUnited States

Locations describe the provider or service region currently used and do not imply that every provider limits all support or operational access to that country.

Buyer FAQ

Straight answers about the controls and commitments available today.

Do you have SOC 2 certification?

No. We publish the controls currently in place and answer security questionnaires directly. If a procurement process requires a specific attestation, we will give a clear answer rather than imply coverage we do not have.

Is a DPA available?

Yes. A Data Processing Agreement is available on request for team, campus, workforce, and outplacement engagements.

Can an organization see individual career data?

No. Organization reporting is limited to program administration and aggregate participation or outcome visibility. Individual resumes, diagnoses, and job-search activity remain private.

Do you offer a standard uptime SLA?

There is no standard public uptime SLA today. Contract-specific availability requirements can be reviewed during enterprise procurement.

How are security incidents handled?

Reports are triaged directly by the operating team. Good-faith vulnerability reports are acknowledged within one business day, and affected customers are notified when an incident materially impacts their data or access.

How do accessibility requests work?

We aim to support WCAG 2.1 AA practices, including keyboard use, semantic structure, labels, and visible focus. Buyers can identify a required accommodation during review so it can be validated against their workflow.

Bring us your requirements.

We will identify what is already supported, what belongs in the agreement, and any requirement the platform does not currently meet.

Start procurement review

Your request is stored securely and routed to the operating team.