You're uploading a document with your employment history on it. Here is exactly what happens to it, described specifically enough that you can hold us to it.
The upload is read into memory, text is extracted, and the buffer is released when the request ends. There is no temporary directory, no object storage bucket, and no database column holding resume content. Nothing to leak later, and nothing for us to hand over.
We check the file’s actual magic bytes rather than trusting its extension, so a renamed executable is not treated as a PDF. Size is capped at 10MB and a 500-byte floor rejects empty files. Text is sanitised of null bytes and control characters before anything else touches it.
Email addresses, phone numbers, LinkedIn/GitHub/social URLs, other personal URLs, postal addresses, PAN numbers, passport-format identifiers, and the candidate name in the resume header are stripped server-side. We explicitly redact Indian national identification numbers from processing. The same stripping runs on the job description you paste, which often contains a recruiter’s direct contact details.
A resume or job posting could contain text addressed to the AI model — asking it to ignore its rules or inflate a score. Our instructions travel in a separate channel from your documents, and each document is fenced with a delimiter generated fresh for that request, so text written beforehand cannot forge a boundary.
Results are cached for 24 hours against a SHA-256 hash of the already-stripped text. The hash cannot be reversed into your resume. An unchanged rescan returns from cache without a second model call.
Scan limits are enforced against shared storage rather than a single server’s memory, so they cannot be bypassed by sending requests in parallel. This protects service availability and keeps automated abuse from running up AI costs.
Telemetry is written only by our server using administrative credentials. Database rules deny all direct client access, so nothing can be read or modified from a browser.
API keys and service credentials are held in server-side environment variables and are never included in the JavaScript sent to your browser.
Security pages usually list only strengths. These are the limits.
If you find a security issue, email workmailkartikeya@gmail.com with enough detail to reproduce it. We aim to acknowledge within 48 hours.
Please give us a reasonable window to fix an issue before disclosing it publicly. We don't run a paid bug bounty, but we will credit you here if you'd like.
Please don't run automated scanners against the live service — it degrades availability for people trying to use the tool, and our rate limiting will block you anyway.
Related: Privacy Policy covers what data we retain and your rights over it. Methodology explains how the score itself is produced.