- In transit: all data uses HTTPS over TLS 1.2+. This applies to the web app, the Chrome extension, and every API call.
- At rest: resume files in Azure Blob Storage use AES-256. Structured records in Azure Cosmos DB are encrypted at rest with Microsoft-managed keys.
- In processing: resume content sent to AI models transits encrypted channels inside the Azure network. AI providers do not retain it after the request completes.
Your resume is sensitive. We treat it that way.
Six commitments. The full detail beneath each one. Read them in the order they matter to you.
TLS 1.2+ in transit. AES-256 at rest in Azure Blob Storage. Microsoft-managed keys for the structured data layer.
We run on Microsoft Azure (SOC 2, ISO 27001, GDPR-compliant). Production access is role-based, audited, and least-privilege.
Your resume is sent to AI providers only for the active request. It is not retained, trained on, or fine-tuned against. This is contractual.
Delete a single resume from your dashboard at any time. Delete the entire account from settings to remove everything within 30 days.
The Chrome extension only fires when you click it. It reads the active job page and nothing else. No background tracking.
Found a security issue? Email security@ajusta.ai. We respond within 48 hours and credit responsible disclosure.
In transit, at rest, in processing.
No training. Period.
- No training on your data. Your resume content is never used to train, fine-tune, or evaluate AI models. This applies to our internal systems and the third-party AI services we use (Azure OpenAI).
- Active request only. Resume content is sent to the model solely to generate the rewrite for your current request. Providers discard it after the request completes.
- Contractual. Our AI processing runs through Azure AI services under Microsoft data processing agreements that prohibit using customer data for model improvement.
You decide when it's gone.
- Delete individual resumes from your dashboard at any time.
- Delete your entire account from settings; all data is permanently removed within 30 days.
- We do not keep backup copies past the 30-day deletion window.
- Optimization history and application tracking are deleted alongside the account.
Least-privilege by design.
- The extension only activates when you explicitly click its icon on a job page.
- It reads only the job description text on the active tab. No other tabs, no history.
- It does not run in the background or track your browsing.
- All extension-to-server traffic is HTTPS.
Reach security directly.
If you discover a security vulnerability, email security@ajusta.ai. We acknowledge within 48 hours, work the fix, and credit responsible disclosure on request.