Authenticated access
Private workspace routes require an authenticated user session outside the test environment.
Security and data controls
ResFlow combines account isolation, encryption, scoped service providers, and candidate-controlled export and deletion. This page describes the current safeguards without claiming absolute security.
Private by account.
Authentication, ownership checks, and row-level rules work together so one candidate cannot browse another candidate’s workspace.
Current safeguards
Private workspace routes require an authenticated user session outside the test environment.
Candidate records are restricted to the authenticated account that owns them.
Saved job descriptions and derived analysis use versioned AES-256-GCM application encryption.
Payload limits, rate limits, server-side validation, and protected API routes reduce avoidable exposure.
Product events are allowlisted, sensitive inputs are masked, and resume or job-description content is not intentionally sent to analytics.
Settings can produce a readable candidate-data export or permanently delete saved workspace data after explicit confirmation.
Providers process only the categories required for their part of the service. Full details and policy links are maintained in the Privacy Policy.
Vercel
Application hosting and request infrastructure
Supabase
Authentication, database, and private storage infrastructure
OpenRouter
Zero-data-retention AI request routing to selected models
PostHog
Allowlisted product analytics and error metadata
Stripe
Managed Payments checkout and subscription management
The Settings page can create a readable export of the candidate records associated with the account.
Permanent account deletion requires typed confirmation and clears saved resumes, analyses, events, private files, and local drafts.
Your next application
Create your private workspace, import your resume, and see the readiness and role-alignment gaps before you export.