Candidate files are processed for one short-lived result.

The live analysis workflow is designed to avoid retaining uploads, extracted text, model payloads, result data, and generated dossiers.

0Uploaded documents retained
0External enrichment sources
NoneCurrent security certification

Follow the live analysis data flow.

Browser to application server

A verified visitor sends one authorized resume and job description over HTTPS.

Validation and suppression

The server validates the file, extracts text, and suppresses specified identity and proxy categories.

Private model request

Only the redacted source text is sent to the configured private inference service.

Verified browser result

The server verifies citations and returns a short-lived result held in browser memory.

Know what is not retained.

Uploads, job descriptions, extracted text, redacted text, model inputs, model outputs, result data, and browser-generated dossiers are not written to a database, object storage, analytics, email, monitoring attachments, or application caches.

Operational analysis records are limited to verification and consent metadata. Marketing retention applies only after separate optional consent.

Training and cross-customer use are prohibited.

Candidate data is not used to fine-tune a model, train a shared model, enrich a profile, or create cross-customer learning. The live analysis workflow reviews only the submitted job description and resume.

Certification status is plain.

Role Evidence does not currently claim SOC 2, ISO 27001, FedRAMP, or another independent security certification. Security controls and deployment facts should be evaluated directly rather than inferred from a badge.

Service roles depend on deployed configuration.

The production architecture anticipates Vercel for application hosting, Supabase for limited operational records, Resend for verification email, Stripe for billing, Cloudflare Turnstile for abuse controls, Modal for private model inference, Plausible for content-free analytics, and Sentry for filtered error monitoring.

The subprocessors page identifies each provider role and the deployment context in which it applies.

Inspect the record fields, not a trust badge.

Draft v0.1 shows the identifiers, citations, suppression record, human review, and lineage fields the product preserves.