Skip to content

Trust, Without Compromise

Swiffit handles two kinds of data: your resume — career history, contact information, employment details — and, on Swiffit Pro, your live call audio and coaching transcripts. Both are protected with enterprise-grade encryption, SOC 2-certified hosting (Vercel + Supabase), and strict data isolation. This page covers how each is captured, processed, and deleted.

256-BIT TLSIn transit
AES-256At rest
SOC 2 HOSTINGVercel + Supabase
GDPRAligned

Protection across every layer

Multiple overlapping security controls ensure no single point of failure.

Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Database connections use SSL certificates. Encryption keys are rotated regularly and managed through secure key management services.

Authentication

Secure authentication via Supabase Auth with bcrypt password hashing, JWT session tokens with short expiry, and support for OAuth providers. Sessions are invalidated on password change.

Access Controls

Row Level Security (RLS) enforced at the database layer ensures users can only access their own data. API routes validate session tokens and enforce authorization on every request.

Data Isolation

Each user's data is logically isolated through row-level policies. Resume content, enhancement history, and personal data are never accessible across accounts — even in the event of an application-level vulnerability.

Network Security

Application deployed on Vercel's edge network with automatic DDoS protection, WAF rules, and TLS termination. Database hosted on Supabase with network-level isolation and connection pooling via PgBouncer.

Infrastructure

Built on SOC 2 compliant infrastructure (Vercel + Supabase). Automated deployments with immutable builds. No SSH access to production. All secrets managed through encrypted environment variables.

Secure Development

Parameterized queries prevent SQL injection. Input sanitization on all user-facing endpoints. Content Security Policy headers. Dependencies audited regularly for known vulnerabilities.

Vulnerability Management

Automated dependency scanning for CVEs. Security patches applied within 48 hours of disclosure. Responsible disclosure program for external researchers. Regular security review of authentication and authorization flows.

How your data moves — call to resume

Swiffit handles two kinds of data differently: live call audio during an active Swiffit Pro coaching session, and the resume content you upload. Here's the full path each one takes, capture to deletion.

Capture

While a Swiffit Pro coaching session is active, the desktop app listens to your microphone and your Mac's system audio — both sides of the call — and transcribes it in real time to generate the on-screen overlay suggestion. Nothing is captured when the app isn't actively coaching.

Processing

Call audio is transcribed and turned into a coaching suggestion by our processor OpenAI — real-time voice transcription and live coaching chat during an active session — or entirely on your Mac if you turn on the on-device transcription option, so audio never has to leave your machine. See the full subprocessor list on our Privacy page.

Screen shares & recordings

In our tests across common screen-share and recording capture paths, the coach overlay didn't appear in the captured output — treat that as tested-not-guaranteed and verify your own setup before a high-stakes call. Hit the panic key (⌘⇧E) any time and everything currently on screen clears instantly.

Deletion & retention

Meeting summaries and transcripts generated during a session are saved to your account's coaching history so you can review past calls — the panic key clears what's on screen but, like any saved record, doesn't retroactively delete history you already generated. Deleting your account (Settings, or contact privacy@swiff.it) removes it the same way it removes your resume data — see Resume Data Lifecycle below for the deletion mechanics and backup timing.

Upload

Your resume is transmitted over TLS 1.3. The original file is stored in encrypted cloud storage with per-user isolation. Text is extracted and structured data is persisted to the database for processing.

Processing

Resume content is sent to Anthropic's Claude API over an encrypted connection under our commercial API terms. Commercial API inputs and outputs are not used for model training by default, and retention depends on the API features and account configuration in use. Processing results are returned to our server and saved to your account.

Storage

Original files are stored in encrypted cloud storage with per-user isolation. Enhanced resumes, scores, and metadata are stored in a Supabase PostgreSQL database with AES-256 encryption at rest. Row Level Security ensures only your authenticated session can access your data.

Deletion

One-click account deletion in Settings removes your production data immediately — resumes, uploaded files, enhancements, diagnostics, and personal information. Encrypted backups roll off on our standard 30-day rotation. Deletion is irreversible.

Responsible AI, by design

Your resume is too important for hallucinations. Here's how we ensure AI accuracy.

  • Designed Never to Fabricate

    Swiffit is designed never to invent credentials, job titles, employment dates, companies, or metrics. The AI enhances how your real experience is presented, and anything it can't trace to your resume or job description is flagged for your review rather than presented as fact.

  • Confidence Flagging

    Every AI change is tagged with a confidence level: High (safe to accept), Medium (minor review recommended), or Verify (AI inferred something you should confirm). You always know what changed and why.

  • No Swiffit Model Training

    Swiffit never uses your resume content to train Swiffit-owned models. Processing with our AI provider, Anthropic, follows our commercial API terms — commercial API inputs and outputs are not used for model training by default, and retention depends on the API features and account configuration in use.

You own your data. Period.

Export all your data at any time from Settings

One-click production deletion, with backups rolling off within 30 days

We never sell your data or share it for marketing purposes

We never claim ownership over content you upload or generate

Enhancement history retained only as long as your account exists

GDPR-aligned data handling for all users, regardless of location

We take security vulnerabilities seriously. If you believe you've found a security issue in Swiffit, please report it responsibly. We ask that you:

  • Email your findings to security@swiff.it
  • Include steps to reproduce the vulnerability
  • Allow reasonable time for us to investigate and patch before public disclosure
  • Do not access or modify other users' data during testing

Contact us at security@swiff.it — we aim to acknowledge reports within 24 hours and resolve critical issues within 72 hours.

Your career data, fully protected

Encrypted, never sold, deletable anytime. Create your free account and see it in action.