- Encryption at rest
- All resumes and analysis records are stored on encrypted Google Cloud Storage with AES-256. Encryption is managed by Google Cloud and applied to every file by default.
- Encryption in transit
- All traffic between your browser, our service, and storage is over TLS 1.2+. We don't allow plain-HTTP connections.
- Tenant isolation
- Multi-tenant by design, isolated by tenant ID at the access-control layer. Your queries can only return your records, enforced server-side, not just hidden in the UI.
- Authentication
- Email + password with strong password requirements, plus optional SSO (SAML 2.0 / OIDC) on Enterprise. All access requires re-authentication on session expiry.
- Data residency
- Default region is US (Google Cloud us-central1). Enterprise customers can request EU or Canada residency under their DPA.
- Backups
- Encrypted daily backups with point-in-time recovery for 30 days. Backups are kept inside the same residency region as your live data.
- Retention & deletion
- Resumes are retained as long as you keep the analysis. Deleting an analysis purges the resumes immediately; backups roll off within 30 days. Account-level deletion on request is permanent.
- No training, no sharing
- We do not use customer resumes to train any model, ever. We do not share resumes, analyses, or any candidate data with third parties for marketing, resale, or benchmarking. The only recipients are the vetted infrastructure and AI processing partners listed under Subprocessors, and only to produce your analysis.
- Subprocessors
- We use a small set of vetted providers: Google Cloud Platform for hosting, storage, and compute; Google Cloud AI / Gemini API for the AI processing that produces your analysis; Stripe for billing on paid plans; an email provider for transactional mail; and, for Enterprise customers using ATS Bridge, the relevant ATS integration partner. The current list is available on request and will be published before any change. See our Privacy Policy, Sharing and subprocessors section, for full detail.
- Access controls (internal)
- Production data access requires named approval, is logged, and is granted only for explicit support cases you've opened. There is no "just-browsing" path to your data.
- Incident response
- If a security incident affects your data, we notify you in writing within 72 hours with a description, scope, and remediation plan.
- Compliance posture
- We follow GDPR principles for data minimization, access, and deletion. Enterprise contracts can include a Data Processing Addendum (DPA). Formal SOC 2 / ISO 27001 attestations are on our roadmap; reach out for our current security questionnaire.