Security

Your job search contains personal context. We treat it that way.

JobSurferAI is designed around private data, user-controlled integrations, and honest limits—especially while the product is in beta.

01

Encrypted secrets

Connected API credentials and OAuth tokens are encrypted before they are stored.

02

Private files

Uploaded resumes are stored in private object storage rather than exposed as public assets.

03

Least access

Google connections request read-only Calendar and Gmail scopes for interview context.

04

Visible controls

Connection status and disconnect actions live in the same Integrations workspace.

How data flows

Only the pieces needed for the workflow.

JobSurferAI stores the information you intentionally add or connect: tracked roles, application details, imported LinkedIn connections, search-agent settings, resumes, and integration credentials.

1
You connect or upload

A job URL, Connections.csv, resume, API key, or Google authorization.

2
JobSurferAI processes privately

Data is stored for your workspace and used to power the workflow you requested.

3
You stay in control

Disconnect Google access or ask for beta data deletion at any time.

Current safeguards

Built for a responsible private beta.

We describe the product as it exists today. JobSurferAI does not currently claim SOC 2 certification or enterprise compliance programs.

AES-GCMCredential encryption before database storage
Read-onlyGoogle Calendar and Gmail data permissions
Private BlobResume file storage configuration
BYOKYour choice of supported AI provider

Questions or reports

Tell us when something deserves attention.

For privacy questions, security reports, or a beta data request, email hello@jobsurferai.com.

Your next role is closer

A focused search, with control built in.

Bring the jobs you care about. JobSurferAI.com helps you organize the work, uncover warm paths, and show up prepared.