Skip to content

SECURITY & CONTROL

Your workspace. Your decisions.

Account boundaries protect access. Deliberate reviews protect the accuracy of your work. These are the controls the current application supports.

ACCESS TO YOUR RECORDS

Private information deserves clear boundaries.

Career evidence and application files belong to your signed-in workspace. Access checks scope records and downloads to that account.

Restricted file permissions and integrity checks are implemented. They do not establish encryption at rest, multi-factor authentication or a compliance certification.

Read how information is handled →

Account controls

  • Passwords are stored as hashes.
  • Email verification is required before sign-in.
  • Sessions expire after eight hours and can be reviewed or revoked in Settings.
  • A successful password reset revokes existing sessions.
  • Session cookies are HttpOnly and SameSite=Lax; Secure applies with configured HTTPS.
  • State-changing forms require a valid security token.

Keep your password and verification/reset links private. Live account email delivery remains deferred.

CONTROL OVER YOUR WORK

Each important decision stays yours.

Confirm the facts

Imported evidence and AI suggestions do not confirm Profile changes. Review what is supported, what conflicts and what remains unknown.

Approve the exact files

Prepared, approved and submitted documents are distinct. Inspect the actual documents before approving a package; later changes do not silently replace submitted versions.

Record what happened

Employer applications, messages and LinkedIn updates happen through your own external process. Copying a draft does not send it.

Control access and copies

Settings offers session management, expiring workspace export and explicit deletion. Disabling sign-in retains records; deletion is a separate action.

What deletion can—and cannot—remove

Deletion removes the live workspace and associated local files. Interrupted physical cleanup requires an operator retry. Hashed erasure evidence remains.

Downloaded files and copies already sent to employers or providers need separate handling. Backup and disaster-recovery qualification remain deferred.

Reporting a security concern

Describe the page, the behavior and the steps needed to reproduce it. Leave out passwords, access tokens, verification links and private attachments.

Contact preparation creates an unsent request, not a support ticket. A public security response time or live support commitment has not been established.

Prepare a report ↗

Know the boundaries before sharing.

Privacy information → Cookies and browser storage →