MeritOS
Enterprise Data Protection

Security & Trust Architecture

Your career documents contain sensitive personal and professional history. We build privacy and encryption into every layer of our stack.

AES-256-GCM Encryption

All sensitive user profile data, work history, and raw resume texts stored in our PostgreSQL database are encrypted at rest using AES-256-GCM field-level encryption with dedicated per-user key isolation.

TLS 1.3 Transport Security

All browser connections, API requests, and webhooks enforce TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) preloading to eliminate man-in-the-middle attack vectors.

1. Data Retention & Privacy Principles

  • Public ATS Scans: Unauthenticated scans on `/ats-check` are processed strictly in-memory and are never stored or sold to third-party recruiters.
  • Account Data: Resumes created inside candidate accounts are retained until explicit account deletion or manual document clearing.
  • 1-Click Deletion: You can purge your profile, resumes, and interview logs permanently from your dashboard settings at any time.

2. Approved Infrastructure Sub-Processors

Sub-processorRole / PurposeLocation
Supabase PostgreSQLEncrypted Relational Database StorageAWS Mumbai / AP-South-1
Clerk Inc.User Identity & Authentication ManagementUS East (SOC-2 Type II Certified)
Groq Cloud Inc.Fast Llama AI Inference (Zero Retention API)US West (Enterprise API SLA)

3. Regulatory Compliance & Data Protection (DPDP & GDPR)

MeritOS operates in strict compliance with India's Digital Personal Data Protection (DPDP) Act 2023 and the EU GDPR. We serve as a Data Fiduciary for candidate records, enforcing explicit user consent, strict purpose limitation, and mandatory data breach notification protocols.