Trust & Security
You bring your working life to Career Convoy — your history, your doubts, your plans. That deserves more than a padlock icon. This page lists the security practices we actually run, the services we rely on, and how we use AI with your data. Every item shows when we last verified it, because a security page that drifts from reality is worse than none. It is generated from our internal security program, not written by marketing.
Our commitments
- Your conversations are yours: never sold, never shared with employers or recruiters, never used to advertise to you.
- We only claim what we can show: everything below traces to evidence in our engineering records.
- If something goes wrong, we tell you: suspected breaches are assessed within 30 days and, if serious harm is likely, we notify affected users and the OAIC — in line with Australia's Notifiable Data Breaches scheme.
Security practices
Dependencies are monitored and vulnerable ones are blocked
Automated scanning reviews our third-party software weekly, and a dependency-review gate blocks known-vulnerable packages from being merged. Critical issues are patched within 7 days. Verified 8 July 2026.
Your data is encrypted in transit and at rest
All traffic uses TLS, and stored data is encrypted at rest by our infrastructure providers. Verified 8 July 2026.
Your conversations are isolated to your account
Every data access in the application is scoped to the signed-in user, with database-level access policies as a second line of defence. Cross-account access is treated as a critical incident. Verified 8 July 2026.
Card details never touch our systems
Payments run on Stripe-hosted Checkout. We never see, transmit, or store your card number. Verified 8 July 2026.
We do not store your raw IP address
Where we need to rate-limit abusive traffic, we store a one-way hash of the IP address, not the address itself, and it expires automatically. Verified 8 July 2026.
We have a rehearsed incident response process
A documented incident runbook covers detection, containment, and recovery — used in earnest, not just written. If we ever suspect a breach of your personal information, we assess it within 30 days and notify affected users and the OAIC if serious harm is likely, in line with Australia’s Notifiable Data Breaches scheme. Verified 8 July 2026.
Your conversations stay out of our operational logs
Our systems keep technical logs so we can fix problems — timings, error codes, and a one-way hash of your account ID. What you actually say to Scout is blocked from those logs in production, and an automated check stops new code from bypassing that. Verified 19 August 2026.
Secrets are managed, never hard-coded
Credentials live in managed environment configuration, never in code or version control, with a documented rotation procedure. Verified 8 July 2026.
How we use AI with your data
- Scout, our career guide, runs on Anthropic’s Claude models. Your conversation content is sent to Anthropic’s API — routed through Vercel’s AI Gateway — solely to generate Scout’s responses, career directions, and your report.
- Under Anthropic’s commercial terms, data sent to their API is not used to train their models. We also switch off storage and model training explicitly on every request we send.
- Scout’s guidance is exactly that — guidance to inform your own decisions. It is never an automated decision made about you, and it is never shared with employers or recruiters.
- If you have questions about how Scout produced something, contact us and a human will answer.
Services we rely on
These providers process data on our behalf. Each one is tracked in our internal vendor register with its agreements and an exit plan.
- Vercel — Application hosting. Data touched: Request traffic, plus operational logs recording technical events against a one-way hash of your account ID.
- Supabase — Database. Data touched: Account-linked conversation and profile data.
- Clerk — Sign-in and account management. Data touched: Name, email, authentication identifiers.
- Stripe — Payments (hosted checkout). Data touched: Payment and billing details (held by Stripe, not us).
- Anthropic — AI processing (Scout runs on Claude). Data touched: Conversation content, transiently, to generate responses.
- Vercel AI Gateway — Routing Scout’s requests to Anthropic. Data touched: Conversation content in transit only — we switch off storage and model training on every request we send.
- Upstash — Rate limiting. Data touched: Hashed IP addresses only (auto-expiring).
- Sentry — Error monitoring. Data touched: Technical error reports.
- Langfuse — Monitoring Scout’s quality, speed and cost. Data touched: Technical measurements such as timings and token counts, against a one-way hash of your account ID. Conversation content is blocked from this in production.
- PostHog — Product analytics (which features people use). Data touched: Feature-usage events against a one-way hash of your account ID. No IP address, no conversation content.
- Cloudflare Turnstile — Bot protection on forms. Data touched: Challenge tokens.
What we collect and why, your rights, and how to delete your data are covered in the Privacy Policy.
Found a security issue?
We want to hear about it. Email us and a founder will respond — please give us a reasonable chance to fix the issue before sharing it publicly. We will not take legal action against good-faith security research.
Email: security@careerconvoy.com.au (or support@careerconvoy.com.au)
Machine-readable details: security.txt