Security & privacy architecture
Trust has to be built before private career data arrives.
Private accounts, uploads, and AI processing stay closed until owner isolation, encryption, file safety, rights, and recovery controls pass production checks.
Review the launch gateThis is a launch gate, not a certification. Private accounts remain closed until production evidence passes.
Launch gate
What must pass before private launch.
Private data
Data rights
Server-only access
Private browser requests go through application APIs. Browsers receive no database or service credentials.
Owner isolation
Private data stays outside the Data API, behind owner-scoped access, least-privilege roles, and encryption.
Evidence before claims
Isolation, file safety, export, deletion, restore, and recovery must pass production acceptance before launch.
The trust gate
Deny first. Verify before enabling.
Keep private accounts, uploads, and AI processing closed until production checks pass.
Verify owner isolation, encryption, quarantine scanning, export, deletion, recovery, and restore behavior.
Publish only controls that match deployed behavior and current evidence.