Security

Security

Last updated: July 19, 2026 Questions? Contact us

Your job search data is sensitive, so we treat it that way. Encryption at rest and in transit, founder-only access controls, and a documented incident response plan. If you find a vulnerability, we want to hear from you.

Security overview

Encrypted

Your data is encrypted at rest and in transit

Secure Auth

Authentication via Better Auth with session isolation

Monitored

Errors and exceptions are tracked and alerted through Sentry

Encryption

All data at rest is encrypted using AES-256. All data in transit is protected with TLS 1.3. Database backups use the same standards, and encryption keys are managed through a managed key management service.

Access Controls

Access to production systems is limited to the founder and requires multi-factor authentication. Production data access is logged. We apply the principle of least privilege and follow security best practices; a formal team training program is not in place.

Browser Extension

Our Chrome extension captures the job posting on the page you're viewing when you click its button. It runs only on your active tab and only when you trigger it; it does not continuously monitor your browsing, read your other tabs, or run on pages you haven't invoked it on.

The extension requests these Chrome permissions: activeTab (temporary access to the tab you click it on, which is how it captures postings on sites like LinkedIn, Indeed, and Glassdoor without standing host access), scripting (read the posting from that tab), storage (your local extension settings), tabs (open RoleReady in a tab and coordinate capture), and downloads (let you save a captured posting or generated document). Host access is limited to https://app.roleready.me/*. The extension does not hold broad host_permissions for LinkedIn, Indeed, Glassdoor, Greenhouse, Lever, Workday, or any other job site, and it does not have access to your logged-in sessions on those sites.

Captured page content is sent to RoleReady over TLS to extract the job's structure (title, company, location, salary, description) and may be sent to our AI provider to refine the extraction. Raw page HTML is processed server-side to extract markdown and structured fields, then discarded; it is not retained. The extension does not set tracking cookies.

Infrastructure Security

RoleReady runs on cloud infrastructure with physical security, redundant power, and network-level DDoS protection. We review our security posture regularly and address vulnerabilities as they come up. Our application and primary database run on Google Cloud in the us-central1 region (United States). File storage runs on Cloudflare R2. Background jobs run on Inngest. AI features route through OpenRouter. Transactional email is sent via Resend. Authentication is handled by Better Auth. Billing is handled by Polar as merchant of record; we do not store full card numbers. See our credits page for more on these tools.

Incident Response

We keep a documented incident response plan. In the event of a data breach, we notify affected users and the relevant authorities within 72 hours, as required by GDPR and applicable law. Security incidents are documented and reviewed to prevent recurrence.

Compliance

We build RoleReady with GDPR, UK GDPR, and CCPA/CPRA in mind. Our Privacy Policy and Data Protection & GDPR Rights page describe how we handle personal data and honor the rights those laws give you. We aren't formally certified and don't claim to be; if you need specifics for a review, email security@roleready.me.

Vulnerability Disclosure

If you discover a security vulnerability in RoleReady, report it to security@roleready.me. We'll acknowledge your report within 48 hours and aim to resolve verified vulnerabilities within 30 days. Please don't publicly disclose a vulnerability until we've had a chance to address it.

Contact

Security team: security@roleready.me