Resumiva is designed around secure sessions, document ownership checks, recoverable drafts and transparent deletion controls.
Short-lived access tokens, rotating refresh sessions, CSRF protection and route ownership checks.
Resume, photo and export queries are scoped to the authenticated user in the API.
Database backups, local draft protection and version history reduce the risk of accidental loss.
Product events should never contain resume text, contact details or uploaded document content.
Account deletion removes resumes, versions, exports, photos and sessions, subject to future billing retention rules.
Security headers, rate limits, health checks, restricted admin routes and protected object storage are part of the release gate.
Do not test against production user data. Send a clear reproduction and impact summary to security@resumiva.com.