How your documents are protected.
Carevra runs on managed cloud infrastructure: encrypted transport, encryption at rest, and tenant isolation enforced in the database rather than in application code. Plain detail below — no certification claims.
Documents are stored in a managed Postgres database with platform encryption at rest.
All traffic between your browser and our servers runs over HTTPS/TLS.
Database policies enforce that you can only ever read your own rows.
Dependencies are scanned automatically and patched as advisories land.
Authentication
Authentication is handled by a managed identity provider. Passwords are stored hashed, never in plain text. Sessions use signed tokens over HTTPS with automatic rotation. Google sign-in is available if you'd rather not hold another password.
Data isolation
Every table that stores user content has row-level security policies enforced at the database layer — not the application layer. This means even an application bug cannot leak one user's resume to another.
AI provider
Tailoring requests are routed to Google Gemini models through a managed AI gateway under terms that prohibit training on the content. We don't fine-tune any model on customer data, and we retain only the document you save to your account.
Backups & deletion
When you delete a resume it is removed from the live database immediately. Encrypted infrastructure backups roll off on the hosting platform's retention schedule, after which no copy remains.
Reporting a vulnerability
We take security reports seriously. Email support@carevra.io with details and we'll respond within 48 hours. Please do not publicly disclose until we've had a chance to investigate and remediate.
Last updated: August 2026