Security & Data Architecture

Your career history isn't just text in a database. It is years of confidential projects, team budgets, strategic decisions, and future salary leverage. Most career apps treat candidate resumes as training fodder for their public AI models or sell lead lists to third-party recruiters. We built CareerWin on the opposite premise: you own your career data, and our systems are engineered to keep it locked down, private, and isolated.

1. 100% Candidate Data Sovereignty

When you paste your resume, connect your LinkedIn profile text, or run a Career Deep-Dive, that data remains your exclusive intellectual property. CareerWin AI LLC (based in King County, Washington) acts solely as a secure custodian. You retain the absolute right to export your entire Master Work Record in structured JSON or PDF format, or permanently delete your account and all associated records with zero pushback.

We do not lock your data in proprietary silos. If you decide to leave CareerWin, you can wipe your footprint completely from active production databases in 30 days.

2. Encryption Architecture (AES-256 at Rest, TLS 1.3 in Transit)

All data stored within CareerWin is encrypted at rest using AES-256 cryptographic standards. This applies to your user profile, structured claims, interview transcripts, and generated application packages.

Every request between your browser and our servers is strictly enforced over TLS 1.3 transport layer security. Intermediaries, network sniffers, and untrusted Wi-Fi connections cannot inspect or tamper with your session.

3. Supabase Row-Level Security (RLS) & Vercel Edge Infrastructure

Our database architecture is hosted on Supabase with strict PostgreSQL Row-Level Security (RLS) policies. RLS acts as a mathematical guardrail at the database engine level: every query is evaluated against the authenticated user ID. Even in the event of an application-level bug, cross-tenant data access is physically prevented by the database engine.

Our application frontend and stateless API routes deploy globally across the Vercel Edge Network, providing automatic DDoS mitigation, isolated serverless execution environments, and zero cross-session data bleeding.

4. Zero Model Training & Ephemeral AI Compute

CareerWin uses enterprise API tiers with frontier foundation model providers (OpenAI, Anthropic, Google DeepMind) to process evidence and structure narrative claims. Under our enterprise data processing agreements:

  • Your resume bullets, private notes, and interview answers are never used to train, retrain, or improve public foundation models.
  • AI vendors act solely as stateless compute processors. Once an inference request is compiled, the ephemeral context window is discarded.
  • We do not sell user data, export candidate lists, or monetize analytics with advertisers or external recruiters.

5. Washington Privacy & Biometric Guardrails

In compliance with the Washington My Health My Data Act (RCW 19.373) and Washington Biometric Privacy laws (RCW 19.375), CareerWin does not collect or infer health or medical records. Any optional voice dictation during interviews is processed strictly for ephemeral speech-to-text transcription. We never capture or store biometric voiceprints.

If you have security inquiries or wish to report a vulnerability, contact our security team directly at richardewing@careerwin.ai.