Identity and access
- Supabase auth
- Per-user workspace isolation
- Role-based admin access
Security
Keep user data private, keep workspaces isolated, and keep the product on a conservative legal path from day one.
Core controls
Before Selling
Every user must only see their own workspaces, packets, and billing state.
Users need a clear path to remove their account data, resumes, and generated packet history.
Billing events, auth state, and packet generation need audit-friendly records without storing unnecessary personal data.
Secret handling
Legal-safe rule
Borrow patterns, not code or branded assets. Use public sources, respect robots, and keep LinkedIn automation off-limits.