Security & privacy architecture

Trust has to be built before private career data arrives.

Private accounts, uploads, and AI processing stay closed until owner isolation, encryption, file safety, rights, and recovery controls pass production checks.

Review the launch gate

This is a launch gate, not a certification. Private accounts remain closed until production evidence passes.

Launch gate

What must pass before private launch.

Not enabled

Access control

AuthenticationSession-boundOwner-scoped

Private data

EncryptedNo browser database accessLeast privilege

Data rights

ExportDeletionRestore checks

Server-only access

Private browser requests go through application APIs. Browsers receive no database or service credentials.

Owner isolation

Private data stays outside the Data API, behind owner-scoped access, least-privilege roles, and encryption.

Evidence before claims

Isolation, file safety, export, deletion, restore, and recovery must pass production acceptance before launch.

The trust gate

Deny first. Verify before enabling.

  1. Keep private accounts, uploads, and AI processing closed until production checks pass.

  2. Verify owner isolation, encryption, quarantine scanning, export, deletion, recovery, and restore behavior.

  3. Publish only controls that match deployed behavior and current evidence.

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice