ResuPulse
Resume ExamplesPricing
Tools
Resume Examples
Pricing
Resources
Company
More
Ask AIUAnalyze Resume
Analyze Resume
ToolsMore
  1. Home/
  2. Security

Trust & Safety

Security and data protection

A resume can contain identity, employment, and contact information. This page separates controls verified in the current application from protections managed by infrastructure providers, and explains the limits visitors should understand before uploading data.

Password protection

Password-based accounts use bcrypt with a work factor of 12. ResuPulse stores the resulting password hash rather than the plain password. Password resets and changes replace credentials instead of revealing an existing password.

Protected session cookies

User access and refresh tokens are sent in HTTP-only cookies with SameSite=Lax. Production cookies are also Secure and use the __Host- prefix. Access tokens expire after 15 minutes, while refresh sessions have their own expiration and revocation records.

Request validation and CSRF controls

API handlers pass through a shared request wrapper that applies CSRF checks to protected writes and funnels errors through one response path. Input schemas, file type checks, file-size limits, and PDF signature checks are applied where relevant.

Ownership and link boundaries

Account-linked tool records and Careers data are checked against the authenticated user before retrieval or modification. Guest tool reports are different: they are not account-owned and can be viewed by anyone with the report link or ID, so those links should be treated as private.

Rate limiting and abuse controls

Authentication, AI tools, support, Careers, and assessment endpoints use purpose-specific limits. Authentication-sensitive limits fail closed if the rate-limit store is unavailable; most product limits fail open so an infrastructure outage does not unnecessarily block the service.

Private Careers file storage

Current Careers resume uploads are validated as PDFs and stored as private objects in AWS S3. Retrieval is proxied through authenticated application routes. PDFs uploaded to public AI tools are read for text extraction but are not deliberately saved to that file store.

Data flow

Data handling and current limits

Security also depends on where data goes, what remains after processing, and which protections are controlled by third-party infrastructure.

Transmission

Browser traffic uses HTTPS. Extracted resume text and tool-specific inputs are sent from ResuPulse to a third-party AI provider for inference, so that provider is part of the processing path rather than an isolated on-device model.

Stored data and at-rest protection

Product records are stored in MongoDB Atlas and Careers resumes are private AWS S3 objects. Access controls are implemented in the application. Infrastructure-level at-rest protection is managed through those providers and their active configuration; ResuPulse does not claim customer-managed encryption keys.

AI-tool retention boundary

AI-tool PDF bytes are not deliberately saved as files, but result records, filenames, content fingerprints, and processing metadata are stored for both guest and account uses. Guest reports can be opened by anyone with their link or ID.

Secrets, logs, and deletion

Service credentials are supplied through environment configuration rather than the client bundle. Routine logs are not designed to include full resume text, but error context may contain personal data. Account export and deletion controls are available; retention details and guest-report deletion guidance are in the Privacy Policy.

Found a security issue?

Send a clear description, affected URL or feature, reproduction steps, and the potential impact. Do not access other users' data, disrupt the service, or publish sensitive details while the issue is being assessed.

[email protected]

Full data-handling policy

Read the Privacy Policy for the complete distinction between AI-tool uploads, server-stored results, Careers files, processors, retention, account controls, and guest-report deletion requests.

data collection and retention details
ResuPulse

Analyze, build, and tailor job-application documents with practical AI tools.

Tools

  • ATS Resume Checker
  • Resume Builder
  • Job Match
  • Compare Resumes
  • Compare for a Job
  • Cover Letter AI
  • LinkedIn Optimizer
  • AI Career Assistant

Resources

  • Career Guides
  • Resume Advice by Industry
  • Glossary
  • Blog & Resources
  • Resume Examples
  • Cover Letter Examples
  • ATS Score Methodology
  • ATS Resume Resources
  • Resume Formats
  • Features
  • Help Center
  • FAQ
  • Pricing

Company

  • About Us
  • Careers
  • Contact Us
  • Security
  • Privacy Policy
  • Cookie Policy
  • Terms of Service
  • AI Disclosure

Careers

  • Open Roles
  • Mission & Values
  • Team & Engineering
  • Careers FAQ

Resume examples by role

Software EngineerData AnalystProduct ManagerDigital Marketing ManagerRegistered NurseAccountantDevOps EngineerUX DesignerBusiness AnalystAccount ExecutiveProject ManagerCustomer Success ManagerAll examples
© 2026 ResuPulse. All rights reserved.
PrivacyCookiesTerms