Security

How we keep your career data safe

Plain-language security practices for Resume.win. We list what is in place today and do not claim certifications we have not completed.

Account protection

  • Passwords are hashed with bcrypt — we never store or email them in plain text.
  • Optional two-factor sign-in with an authenticator app, plus one-time recovery codes. Authenticator secrets are encrypted before storage.
  • Email verification with one-time codes before a new account is active.
  • Review active sessions and sign out other devices from your account Settings.
  • Sign in with Google or Microsoft if you prefer not to manage another password.

Data protection

  • All traffic is served over HTTPS, with HTTP Strict Transport Security enforced in production.
  • Resume and logo files live in private cloud storage. Every download checks that you own the file.
  • Our database and storage providers (MongoDB Atlas and Microsoft Azure) encrypt data at rest.
  • Apply Packs are shared only through links you create, and you can revoke them. Public profiles are opt-in.
  • Export everything or delete your account yourself from Settings — including accounts created with Google or Microsoft.

How AI uses your data

  • When you run an AI feature, only the content needed for that request (for example, your resume and the job description) is sent to our AI provider.
  • We instruct providers to use that data to answer your request — not for public model training.
  • AI suggestions are drafts. You review and choose what goes into an application; nothing is submitted to employers on your behalf.
  • AI output never makes hiring decisions about you. You can ask for human review where the law requires it.

Application hardening

  • A Content Security Policy, frame-ancestor blocking, and MIME-sniffing protection on every page.
  • Rate limits on sign-in, AI, and other sensitive endpoints to slow brute-force and abuse.
  • Payments run through Stripe Checkout. Card numbers never touch our servers.
  • Production error monitoring so we see and fix failures quickly.

What we do not claim

We do not currently hold SOC 2, ISO 27001, or HIPAA certification, and we do not run a paid bug bounty. If that changes, we will publish the evidence here and on the Trust Center. Our full list of service providers is on the DPA & subprocessors page.

Report a vulnerability

Found a security issue? Email [email protected] with the subject “Security report”. Our machine-readable contact is at /.well-known/security.txt.

Please include the affected URL, steps to reproduce, and the impact you observed. Test only against your own account, do not access or change other users' data, and give us reasonable time to fix the issue before sharing it publicly. We will not pursue good-faith research that follows these rules.