Security & Trust Architecture
Your career documents contain sensitive personal and professional history. We build privacy and encryption into every layer of our stack.
AES-256-GCM Encryption
All sensitive user profile data, work history, and raw resume texts stored in our PostgreSQL database are encrypted at rest using AES-256-GCM field-level encryption with dedicated per-user key isolation.
TLS 1.3 Transport Security
All browser connections, API requests, and webhooks enforce TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) preloading to eliminate man-in-the-middle attack vectors.
1. Data Retention & Privacy Principles
- Public ATS Scans: Unauthenticated scans on `/ats-check` are processed strictly in-memory and are never stored or sold to third-party recruiters.
- Account Data: Resumes created inside candidate accounts are retained until explicit account deletion or manual document clearing.
- 1-Click Deletion: You can purge your profile, resumes, and interview logs permanently from your dashboard settings at any time.
2. Approved Infrastructure Sub-Processors
| Sub-processor | Role / Purpose | Location |
|---|---|---|
| Supabase PostgreSQL | Encrypted Relational Database Storage | AWS Mumbai / AP-South-1 |
| Clerk Inc. | User Identity & Authentication Management | US East (SOC-2 Type II Certified) |
| Groq Cloud Inc. | Fast Llama AI Inference (Zero Retention API) | US West (Enterprise API SLA) |
3. Regulatory Compliance & Data Protection (DPDP & GDPR)
MeritOS operates in strict compliance with India's Digital Personal Data Protection (DPDP) Act 2023 and the EU GDPR. We serve as a Data Fiduciary for candidate records, enforcing explicit user consent, strict purpose limitation, and mandatory data breach notification protocols.