Trust
Security at CareerScope
CareerScope handles résumés and career preferences—data that deserves careful defaults, tight access, and a clear path to report issues.
Encryption
Data in transit is protected with TLS. Sensitive credentials are never stored in plaintext. Database and storage access is limited to authenticated service pathways.
Authentication
Accounts use Supabase Auth with email verification flows and Sign in with Apple on iOS. Sessions are token-based and can be revoked by signing out or deleting the account.
Supabase security
Application data lives in PostgreSQL on Supabase with least-privilege service access, row-level security policies where applicable, and environment-separated keys for production.
Data protection
Résumés, questionnaire answers, and saved jobs are account-scoped. We do not sell personal data. Processors (OpenAI, Adzuna, hosting) are used under contractual terms to operate features you request.
Operational practices
- Principle of least privilege for production credentials
- Dependency and platform updates as part of release hygiene
- Account deletion pathways for user-controlled data removal
- Separate handling of marketing site vs. authenticated app data
Responsible disclosure
If you believe you have found a security vulnerability in CareerScope or yourcareerscope.com, please email legal@yourcareerscope.com with details and steps to reproduce. Please do not publicly disclose the issue until we have confirmed a fix or provided guidance. We appreciate good-faith researchers.
User tips
- Use a unique password if signing in with email
- Prefer Sign in with Apple on shared devices when available
- Keep iOS updated
- Delete your account if you no longer need CareerScope
