Loading page content
Loading
Preparing your experience
Please wait while we fetch the latest data and prepare the page for you.
Loading
Preparing your experience
Please wait while we fetch the latest data and prepare the page for you.
Local-first browser storage, decoupled document sandboxes, and cloud sync you explicitly opt into, never by surprise.
We never monitor or transmit your document typing.
HTTPS on every connection. At-rest encryption is provided by our infrastructure providers.
A named point of contact who acknowledges every security report.
Transparent open-source architecture on GitHub.
Click across the 4 architecture layers to inspect how each environment protects your data.
Interactive multi-layered architecture
Your documents compile in-browser using vector rendering. Zero telemetry on your keystrokes.
We believe in total transparency regarding where your information is processed and stored across our client-first stack.
Documents are drafted and rendered in your browser, and your drafts live in that browser's storage. Nothing is sent to us during document generation. Note that browser storage is not encrypted by us: on a shared or compromised machine, treat it as readable.
When you register and log in, your Master Profile and documents sync over an encrypted connection, with passwordless OTP verification handled by Better Auth. Storage-layer encryption is provided by our hosting and database providers under their terms, not implemented by us.
Portfolios published to a veriworkly.com subdomain are served over HTTPS. Visitor counts are aggregated without third-party tracking cookies. Unpublishing takes the page private immediately, clears our own cache, and asks the public site to regenerate — allow a short window for any intermediate caches outside our control to catch up.
AI tailoring and cover letter drafting send your text to a third-party model provider. We do not store the prompt or the response beyond the request, and we do not train models on your data — but the text does leave our infrastructure, which is why every AI action is something you trigger deliberately.
VeriWorkly follows the principle of least privilege. We never request write permissions, organization administration, or access to private repository source code.
Scope: Better Auth defaults (no elevated scopes requested)
Signs you in, and imports public repository names, stars, descriptions, and primary languages for your profile projects. Only your own connected account is importable on the free tier.
Scope: Text you paste or upload yourself
Turns exported LinkedIn text into structured career history, positions, education, and skills.
Scope: Email OTP Verification
Authenticates account ownership via short-lived numeric one-time passcodes delivered to your email.
We do not monetize or hold user data indefinitely. Review our exact retention timelines and deletion methods across each platform subsystem.
| Platform Area | Storage Location | Retention Period | Deletion Method |
|---|---|---|---|
Unauthenticated Studio EditorHeld in your browser; not encrypted by us | Browser LocalStorage (Client-Only) | 0 days on server (Persists in browser until cleared) | 1-click 'Clear Cache' button or browser data wipe |
AI Resume & Bullet OptimizationHTTPS in transit; request text not retained | In memory, plus a third-party model provider | 0 days with us; provider terms apply to the request itself | Automatic session teardown post-request |
Synced Master Profile & DocumentsHTTPS in transit; at-rest encryption per our providers | PostgreSQL database (opt-in sync) | Active account duration | 1-click account deletion; records removed from our database |
Published Web PortfoliosAutomated edge HTTPS | Published page, plus our own cache | While published | 'Unpublish' takes it private, clears our cache, and triggers regeneration |
Security Triage ReportsEmail over TLS (we do not currently publish a PGP key) | Security inbox | 90 days post-resolution (compliance audit log) | Automated purge after audit cycle |
Report it privately and we will work it through with you. We do not run a paid bug bounty, so we cannot offer money — what we can offer is a fast, honest response and credit where you want it.
Send the details directly to [email protected]. Please do not open a public issue or post publicly before a fix is out.
We confirm receipt within 24 to 48 hours. VeriWorkly is maintained by a small team, so this is a target we can hold rather than a contractual SLA.
We reproduce the issue, agree a severity with you, and patch it before any public disclosure. We will tell you honestly if a fix is going to take time.
Once the fix is live we coordinate disclosure with you, and credit you by name in the release notes if you would like to be named.
If you make a good-faith effort to follow this policy while researching a vulnerability, we will treat your testing as authorised. We will not pursue or support legal action against you, and if a third party brings action over research that followed this policy, we will make it known that your testing was authorised. Stay within scope, work only with your own accounts and data, do not degrade the service for others, do not access or retain anyone else's personal data, and give us a reasonable chance to fix the issue before disclosing it. If you are unsure whether something is in scope, ask us first — we would rather answer the question than have you guess.
Goes straight to the maintainer, not a ticket queue.
No account creation required to start. Export recruiter-approved ATS PDFs and publish your live web portfolio instantly.
Built responsive templates using standard styling protocols.