Privacy, verified

Your resume never reaches the AI with your contact info attached.

Most tools upload your resume to an AI provider exactly as you wrote it — Social Security number, email, phone, home address, and all. We don't. Here's what actually happens between "upload" and "tailored resume."

Read the full privacy policy
Resumes tailored
Post-scrub leak checks passed
PII items removed
0
Raw resume text stored
Step 1

Scrubbed in your browser

Before your resume leaves your device, we strip Social Security numbers (all formats — dashed, dotted, spaced, bare), email addresses, U.S. phone numbers, street addresses, and your name.

Step 2

Encrypted in transit

Only the scrubbed text is sent over HTTPS to our server. Your raw resume never leaves your browser.

Step 3

Re-scrubbed on our server

On arrival, we run the same scrubber again — a belt-and-suspenders check — before anything is stored or sent to the AI model.

Step 4

Logged, then verified clean

Every run writes an audit row with counts only — no resume text — and runs a "leak check" that must come back clean before we return your tailored resume.

What our internal audit log looks like

This is a real snapshot from our admin audit log — with user IDs and model info removed. Notice what's not here: your resume text, your job description, and the AI's response. Only counts and a pass/fail leak check.

WhenChars (raw → scrubbed)RedactionsLeak check
8:29 PM4,387 → 4,377SSN 0 · Email 2 · Phone 1 · Addr 3 · Name 1 clean
8:26 PM3,567 → 3,567SSN 1 · Email 0 · Phone 0 · Addr 1 · Name 0 clean
7:54 PM3,571 → 3,567SSN 0 · Email 0 · Phone 0 · Addr 1 · Name 0 clean
7:49 PM3,575 → 3,571SSN 0 · Email 0 · Phone 0 · Addr 1 · Name 0 clean
7:06 PM3,575 → 3,571SSN 0 · Email 0 · Phone 0 · Addr 1 · Name 0 clean
Platform security

Enterprise-grade controls under the hood.

For companies and non-profit partners (from defense primes to veteran-hiring non-profits) evaluating JobSearchFix AI for their people: here's how the underlying platform is secured.

SOC 2 Type II GDPR ISO 27001 Encrypted at rest & in transit Role-based access
Step A

Regional data residency

Customer data is hosted in supported regions (US, EU, Australia) and does not move across regions by default.

Step B

Isolation by design

Each workspace and project is logically separated. Your data is not accessible across accounts, and environment boundaries are enforced server-side.

Step C

Secrets, encrypted & scoped

API keys and secrets are encrypted at rest, scoped to specific environments, never exposed in logs or the UI, and rotatable without a full redeploy.

Step D

Continuous security scanning

Automated scans run on every publish — database configs, access rules, and known misconfiguration patterns — plus deeper on-demand codebase scans and continuous dependency checks.

Step E

Not used to train AI models

Your resume, prompts, and workspace data are not used to train foundation models. Contracts with AI providers restrict training and retention of customer data.

Step F

Abuse detection & rate limiting

Platform activity is continuously monitored for anomalous behavior, with adaptive rate limiting at the IP, user, and workspace level.

What we never do

  • ❌ Sell your resume, job history, or contact info.
  • ❌ Use your resume to train foundation AI models.
  • ❌ Store your raw resume text in our audit logs.
  • ❌ Send your Social Security number, home address, or personal email to any AI provider.
  • ❌ Share your data with recruiters or employers without your explicit action.

Try it — safely.

Upload a resume with real contact info. Watch the toast tell you exactly what was scrubbed before anything left your browser.