TRUST CENTER
Trust, Without Compromise
Swiffit handles two kinds of data: your resume — career history, contact information, employment details — and, on Swiffit Pro, your live call audio and coaching transcripts. Both are protected with enterprise-grade encryption, SOC 2-certified hosting (Vercel + Supabase), and strict data isolation. This page covers how each is captured, processed, and deleted.
Protection across every layer
DEFENSE IN DEPTH
Multiple overlapping security controls ensure no single point of failure.
Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Database connections use SSL certificates. Encryption keys are rotated regularly and managed through secure key management services.
Authentication
Secure authentication via Supabase Auth with bcrypt password hashing, JWT session tokens with short expiry, and support for OAuth providers. Sessions are invalidated on password change.
Access Controls
Row Level Security (RLS) enforced at the database layer ensures users can only access their own data. API routes validate session tokens and enforce authorization on every request.
Data Isolation
Each user's data is logically isolated through row-level policies. Resume content, enhancement history, and personal data are never accessible across accounts — even in the event of an application-level vulnerability.
Network Security
Application deployed on Vercel's edge network with automatic DDoS protection, WAF rules, and TLS termination. Database hosted on Supabase with network-level isolation and connection pooling via PgBouncer.
Infrastructure
Built on SOC 2 compliant infrastructure (Vercel + Supabase). Automated deployments with immutable builds. No SSH access to production. All secrets managed through encrypted environment variables.
Secure Development
Parameterized queries prevent SQL injection. Input sanitization on all user-facing endpoints. Content Security Policy headers. Dependencies audited regularly for known vulnerabilities.
Vulnerability Management
Automated dependency scanning for CVEs. Security patches applied within 48 hours of disclosure. Responsible disclosure program for external researchers. Regular security review of authentication and authorization flows.
DATA LIFECYCLE
How your data moves — call to resume
Swiffit handles two kinds of data differently: live call audio during an active Swiffit Pro coaching session, and the resume content you upload. Here's the full path each one takes, capture to deletion.
CALL DATA
Capture
Processing
Screen shares & recordings
Deletion & retention
RESUME DATA
Upload
Processing
Storage
Deletion
AI INTEGRITY
Responsible AI, by design
Your resume is too important for hallucinations. Here's how we ensure AI accuracy.
Designed Never to Fabricate
Swiffit is designed never to invent credentials, job titles, employment dates, companies, or metrics. The AI enhances how your real experience is presented, and anything it can't trace to your resume or job description is flagged for your review rather than presented as fact.
Confidence Flagging
Every AI change is tagged with a confidence level: High (safe to accept), Medium (minor review recommended), or Verify (AI inferred something you should confirm). You always know what changed and why.
No Swiffit Model Training
Swiffit never uses your resume content to train Swiffit-owned models. Processing with our AI provider, Anthropic, follows our commercial API terms — commercial API inputs and outputs are not used for model training by default, and retention depends on the API features and account configuration in use.
You own your data. Period.
EXPORT
Export all your data at any time from Settings
DELETION
One-click production deletion, with backups rolling off within 30 days
NO SALE
We never sell your data or share it for marketing purposes
OWNERSHIP
We never claim ownership over content you upload or generate
RETENTION
Enhancement history retained only as long as your account exists
GDPR
GDPR-aligned data handling for all users, regardless of location
RESPONSIBLE DISCLOSURE
We take security vulnerabilities seriously. If you believe you've found a security issue in Swiffit, please report it responsibly. We ask that you:
- Email your findings to security@swiff.it
- Include steps to reproduce the vulnerability
- Allow reasonable time for us to investigate and patch before public disclosure
- Do not access or modify other users' data during testing
Contact us at security@swiff.it — we aim to acknowledge reports within 24 hours and resolve critical issues within 72 hours.