Security and privacy at CVPitch
How CVPitch protects candidate CVs: workspace isolation, SSO, contact removal with metadata checks, retention, AI limits and integration safeguards.
Agencies trust us with candidates' CVs, which contain some of the most personal information people share. This page sets out CVPitch security and privacy practices factually: how we handle that data and what we do and do not claim. Our privacy page sets out the legal details, including the hosting region and model provider, and our GDPR guide for agencies covers your own obligations.
Access and workspace isolation
- Every request is checked against authenticated membership. Your agency's data belongs to your workspace, and the workspace is determined from your signed-in membership, never from an identifier supplied in the request.
- Roles. Owners manage templates, retention, billing, integrations and security settings; recruiters prepare, review and export CVs.
- Passwords are hashed with Argon2. Session tokens are stored hashed, and changes made through the browser require a CSRF token.
- Single sign-on. Owners can connect an identity provider over OIDC or SAML 2.0 after proving control of the email domain with a DNS record. ID tokens and SAML responses are verified against your provider's keys or certificates, with audience, expiry and replay checks. An owner can require SSO for the workspace while keeping one named owner able to sign in with a password in an emergency.
- Email verification is required before a workspace can upload CVs.
- Concurrent edits are detected, so one recruiter cannot silently overwrite another's work.
- Audit log export. Owners can download workspace activity, such as uploads, approvals, shares, SSO sign-ins and settings changes, as a CSV file.
Candidate documents
- Originals are kept separately from generated files and public assets, and are never overwritten.
- Uploads are validated before processing: PDF, Word (DOCX and DOC), RTF, ODT, TXT and PNG, JPEG, WebP or TIFF images, recognised by their content rather than their name, up to 10 MiB, with PDFs and scans up to 20 pages and 120,000 characters of text. Password-protected files and documents that link to outside content are refused.
- Documents are treated as data. Text inside a CV, including text read from a scan, can never act as an instruction to the AI or to any integration.
- Conversion and rendering are isolated. Older Word, RTF and ODT files are converted, images are re-encoded without their metadata, and Word and PDF files are generated by a separate document service that runs in its own locked-down container without internet access.
- Agency Word templates are checked. An uploaded template is rejected if it contains macros, embedded objects, external links or fields that pull in outside content. Comments, tracked changes, hidden data and document properties are stripped before it is stored. Templates are fill-in only, and text from a CV cannot add new tags.
Contact removal and anonymisation
You choose which contact details the client should not see: email, phone, address and personal links, or the name replaced with a candidate reference. You can also remove date of birth, age, nationality, visa, gender, marital status and religion lines, and mask employers and institutions with descriptors. Removal is applied to the generated DOCX, the PDF and their hidden document metadata, and logo files have their metadata removed during generation. After each file is generated, CVPitch checks that removed contact details and masked names appear nowhere in the Word package or in the PDF's text and metadata, and rejects the file if they do. The original CV is not changed.
Contact removal is not complete anonymisation. Personal-detail detection relies on English labels and phrasing, and a distinctive career history can still identify someone, and we say so in the product. See CV redaction and CV anonymisation.
Approval and export integrity
- Approval is tied to the exact revision, the client template version and the contact-removal policy. Any later change, including accepted AI suggestions and restored versions, invalidates the approval.
- Exports come from one approved snapshot, so the Word file and PDF match each other and the approved facts. JSON exports, shortlists, web profiles and share links are built from approved snapshots too, never from unapproved edits.
- Draft previews are separate and visibly marked as drafts.
- Every fact shows its origin: extracted with source evidence, unverified, recruiter-corrected, recruiter-added or AI-assisted.
- Spreadsheet exports contain no formulas. Shortlist cells are written as plain text, so a value in a CV cannot run as a spreadsheet formula.
Retention and deletion
- You set retention for your workspace from 1 to 90 days. Submissions older than that are removed automatically.
- Delete at any time. Deleting a submission revokes access immediately, removes it from shortlists and the talent page, and queues the stored files for removal.
- A deletion journal on separate infrastructure records each deletion using IDs and a timestamp only, never CV content, so deletions are re-applied if data ever has to be restored.
- Email intake logs record the sender, time, attachment count, outcome and email-authentication results, and are kept for 30 days. The email's subject and body are never stored.
- Talent page enquiries (the enquirer's name, email, company and message) are kept for 180 days unless you delete them sooner.
AI processing
- Provider: extraction, text recognition (OCR) for scans and photos, and the AI writing tools use Anthropic's Claude (Haiku model). See the privacy page for provider and transfer details.
- Bounded use: each request has a hard cost cap, retries are limited, and a monthly processing budget applies across the service. AI credits meter optional AI features separately from exports.
- No tools for the model: the AI cannot browse, call integrations or take actions; it returns structured data that is validated before use.
- Evidence is checked: every extracted value must appear word for word in a quote that matches the source exactly. If it does not, the extraction is rejected rather than showing an unsupported fact. For scans and photos the source is the AI transcription, so the CV carries a review flag until a recruiter has checked it against the image.
- AI writing is a proposal: rewrites, summaries, proofreading, chat edits and translations are shown as changes to accept or reject. The tools receive only the fields they need, never the candidate's name or contact details. Rule-based checks drop suggestions that change protected facts or add numbers, links or names not found in the CV.
- Job matching is deterministic: requirement statuses come from rules applied to the CV text, not from an AI judgement.
Analytics, logs and support
- Candidate text is never sent to analytics. Third-party advertising and analytics tags run only on our public marketing pages, never inside the workspace, on sign-in and sign-up pages, or on the free tool pages where you paste CV text.
- Free tools run in your browser. The anonymiser, keyword, personal-data and bias checkers analyse text locally. When you upload a file to a tool, the server extracts its text and returns it without storing or logging it.
- Consent first where required. In the EEA, the UK and Switzerland, optional tags stay off until you allow them, and a Global Privacy Control signal is treated as an opt-out.
- Our own page counts are cookieless and do not store IP addresses.
- Logs and error reports are designed to exclude CV text.
- Support requests should never include CVs or candidate details; please keep them out of tickets and emails.
- Payments, including AI credit packs, are processed by Gumroad. We do not see or store card numbers.
Integrations
- Scoped credentials. API keys and OAuth grants carry only the permissions you choose, are shown once, stored hashed and can be revoked. OAuth uses PKCE and an explicit consent screen.
- ATS and CRM connections are managed by owners. Credentials are encrypted at rest, tested before saving and never shown again. Data moves only when a recruiter imports a chosen CV or sends chosen approved files, and vendor error messages are never passed through.
- Email intake accepts mail only from workspace members and addresses the owner allows, and only when the sender's domain passes email authentication. Unknown and automated senders get no reply, and final files are sent only to active members.
- No approval by machines. Neither the API, AI assistants, email intake nor ATS connectors can approve a submission.
- Candidate evidence is opt-in. Assistants can read selected facts only when a workspace owner enables sharing, with masking applied and recruiter notes withheld.
- Metadata-only events. Webhooks and chat notifications carry IDs, statuses and links, never CV text.
- Signed webhooks use HMAC-SHA256, and destinations must be public HTTPS endpoints.
- Short-lived downloads. Download links for approved files expire after five minutes and only work for the credential that created them.
Details are on the integrations and developers pages, and every safeguard here applies on every plan; see features and pricing.
Where candidate data goes
Apart from our hosting and backups, candidate data is sent outside CVPitch only in these cases:
- To our AI provider for extraction, text recognition and the AI writing tools you use.
- To our email provider, Resend, when CVs are forwarded to your intake address, and when you choose to have approved files emailed back to the recruiter who sent them.
- To the ATS or CRM you connect, when a recruiter imports a CV from it or sends approved files to it. These transfers happen at your direction, to a vendor you chose.
- To your AI assistant's provider, only if an owner turns on evidence sharing for Claude or ChatGPT.
- To your clients, through share links, shortlists and the talent page you create.
Share links and the talent page
Client share links work only for approved CVs, expire, can be revoked at any time, and are not indexed by search engines. They record opens, downloads and the client's response so you know what was seen. Unique visitors are counted with a keyed hash; IP addresses and browser details are not stored.
The talent page is off until an owner turns it on. Each profile needs a recruiter to confirm the candidate's consent, expires after at most 90 days, and never shows names, contact details or summaries. Search-engine indexing stays off unless the owner allows it. If you use a custom client domain, it serves only share pages and the talent page, never sign-in or the workspace.
What we do not claim
- CVPitch does not currently hold third-party security certifications such as SOC 2 or ISO 27001.
- We do not describe CVPitch as "GDPR certified" or "GDPR compliant" on its own; compliance depends on how each agency collects and uses candidate data.
- AI extraction and text recognition can be wrong, and the checks on AI writing are rule-based and can miss a change. That is why every fact shows its evidence and a recruiter must approve.
- We cannot confirm your lawful basis for processing a candidate's data or your right to represent them; that remains your responsibility.
- Edits made to an exported Word file outside CVPitch are not checked.
Reporting a security issue
If you believe you have found a vulnerability, email support@cvpitch.app with the details and steps to reproduce. Please do not include real candidate data in your report, and give us reasonable time to fix the issue before disclosing it.
Frequently asked questions
Who can see our candidates' CVs?
Only members of your agency's workspace, plus the clients you share approved CVs with. Access is checked against authenticated membership on every request, and candidate text is never sent to analytics, notifications or webhooks.
How long does CVPitch keep CVs?
As long as your workspace's retention setting, from 1 to 90 days, unless you delete a submission sooner. Deletion revokes access immediately and queues stored files for removal.
Is candidate data used to train AI models?
CVPitch does not train AI models on your data. Extraction, text recognition and AI writing are performed by Anthropic's Claude; see our privacy page for the provider and data transfer details.
Does CVPitch support single sign-on?
Yes. Owners can connect Microsoft Entra ID, Google Workspace, Okta or another provider over OIDC or SAML 2.0, verify their email domain and require SSO for the workspace.
Is CVPitch GDPR compliant?
We provide controls that support your obligations: contact removal, retention limits, deletion, workspace isolation and transparency about processors. Compliance also depends on how your agency collects and uses candidate data, so read our GDPR guide and the privacy page. Start a free trial to review the settings.
Turn your next CV into a client-ready submission
Upload a candidate CV, check every fact against the source, remove contact details and export your agency’s branded DOCX and PDF. Your first 10 CVs are free.