How we keep your career safe.
The Career OS holds your resume, applications, offers, and career story. That’s serious. Here’s how we protect it.
Encryption
All data in transit is TLS 1.2+. All data at rest is encrypted using industry-standard AES-256.
Authentication
We use Clerk for authentication with support for passwordless email links, OTP, and SSO. Sessions are short-lived and refreshed on activity.
Access controls
Only the account owner can access their data. Support staff cannot view your resumes, applications, or offers without your explicit consent via a support session.
Storage
Uploaded documents live in a private object store with signed URLs. AI responses and metadata live in MongoDB. Nothing is stored in plaintext where it doesn’t need to be.
Incident response
We follow a documented incident response playbook. Any material incident is disclosed to affected users within 72 hours.
Reporting a vulnerability
Please email security@notcookedjobs.dev. We do not currently have a public bug-bounty program during Beta, but we recognise reporters in the Release Notes.