Security controls
- Supabase authentication and owner-scoped row-level security protect account records.
- CV storage is private and separated by user identifier.
- Server-only credentials are excluded from browser bundles.
- Inbound webhooks require feature flags, signatures and idempotency identifiers.
- Live submission, email and billing providers default to off until their safety gates pass.
Report a vulnerability
Use Contact and begin the message with “Security disclosure”. Include the affected URL, impact, safe reproduction steps and a contact address. Do not include credentials, other users' personal information or active exploit payloads.
Safe testing rules
Do not access another person's account or data, cause service degradation, send spam, upload malware, perform denial-of-service testing, use social engineering, test third-party providers, or retain information encountered accidentally. Stop immediately if you encounter personal information.
What happens next
We will acknowledge a reproducible report, assess severity, preserve relevant evidence and coordinate a proportionate fix. Public disclosure should wait until a fix is available and users are no longer exposed.