CarevraCarevra
Security

How your documents are protected.

Carevra runs on managed cloud infrastructure: encrypted transport, encryption at rest, and tenant isolation enforced in the database rather than in application code. Plain detail below — no certification claims.

Encrypted at rest

Documents are stored in a managed Postgres database with platform encryption at rest.

Encrypted in transit

All traffic between your browser and our servers runs over HTTPS/TLS.

Row-level security

Database policies enforce that you can only ever read your own rows.

Scanned dependencies

Dependencies are scanned automatically and patched as advisories land.

Authentication

Authentication is handled by a managed identity provider. Passwords are stored hashed, never in plain text. Sessions use signed tokens over HTTPS with automatic rotation. Google sign-in is available if you'd rather not hold another password.

Data isolation

Every table that stores user content has row-level security policies enforced at the database layer — not the application layer. This means even an application bug cannot leak one user's resume to another.

AI provider

Tailoring requests are routed to Google Gemini models through a managed AI gateway under terms that prohibit training on the content. We don't fine-tune any model on customer data, and we retain only the document you save to your account.

Backups & deletion

When you delete a resume it is removed from the live database immediately. Encrypted infrastructure backups roll off on the hosting platform's retention schedule, after which no copy remains.

Reporting a vulnerability

We take security reports seriously. Email support@carevra.io with details and we'll respond within 48 hours. Please do not publicly disclose until we've had a chance to investigate and remediate.

Last updated: August 2026