▸ Security

    Your resume is sensitive. We treat it that way.

    Six commitments. The full detail beneath each one. Read them in the order they matter to you.

    Last reviewed Mar 2026
    Encryption everywhere

    TLS 1.2+ in transit. AES-256 at rest in Azure Blob Storage. Microsoft-managed keys for the structured data layer.

    Azure infrastructure

    We run on Microsoft Azure (SOC 2, ISO 27001, GDPR-compliant). Production access is role-based, audited, and least-privilege.

    Not training data

    Your resume is sent to AI providers only for the active request. It is not retained, trained on, or fine-tuned against. This is contractual.

    Delete on demand

    Delete a single resume from your dashboard at any time. Delete the entire account from settings to remove everything within 30 days.

    Extension is least-privilege

    The Chrome extension only fires when you click it. It reads the active job page and nothing else. No background tracking.

    Report a vulnerability

    Found a security issue? Email security@ajusta.ai. We respond within 48 hours and credit responsible disclosure.

    ▸ Encryption

    In transit, at rest, in processing.

    • In transit: all data uses HTTPS over TLS 1.2+. This applies to the web app, the Chrome extension, and every API call.
    • At rest: resume files in Azure Blob Storage use AES-256. Structured records in Azure Cosmos DB are encrypted at rest with Microsoft-managed keys.
    • In processing: resume content sent to AI models transits encrypted channels inside the Azure network. AI providers do not retain it after the request completes.
    ▸ AI processing and your data

    No training. Period.

    • No training on your data. Your resume content is never used to train, fine-tune, or evaluate AI models. This applies to our internal systems and the third-party AI services we use (Azure OpenAI).
    • Active request only. Resume content is sent to the model solely to generate the rewrite for your current request. Providers discard it after the request completes.
    • Contractual. Our AI processing runs through Azure AI services under Microsoft data processing agreements that prohibit using customer data for model improvement.
    ▸ Retention and deletion

    You decide when it's gone.

    • Delete individual resumes from your dashboard at any time.
    • Delete your entire account from settings; all data is permanently removed within 30 days.
    • We do not keep backup copies past the 30-day deletion window.
    • Optimization history and application tracking are deleted alongside the account.
    ▸ Chrome extension

    Least-privilege by design.

    • The extension only activates when you explicitly click its icon on a job page.
    • It reads only the job description text on the active tab. No other tabs, no history.
    • It does not run in the background or track your browsing.
    • All extension-to-server traffic is HTTPS.
    ▸ Reporting issues

    Reach security directly.

    If you discover a security vulnerability, email security@ajusta.ai. We acknowledge within 48 hours, work the fix, and credit responsible disclosure on request.