Building in GRCHome

Trust Center

Security and privacy practices

Building in GRC processes career information. Public portfolios are off by default. We do not claim SOC 2, ISO 27001, GDPR, or HIPAA certification because our infrastructure providers hold those certificates. Shared-responsibility still applies: our application controls must be verified.

What we collect

Career profile, skills, evidence you choose to submit, job descriptions you paste, and Scenario Lab practice. We do not collect SSNs, government IDs, health information, or credentials as product fields.

Privacy defaults

  • Public portfolio is opt-in.
  • You choose which case studies are listed.
  • Readiness scores, gaps, job analyses, private notes, scenario scores, 360 feedback, compensation notes, and raw evidence stay private.

AI data use

MVP job analysis and promotion drafts run in-process with declared minimum fields. No live model is called. When a provider is added, each task must declare allowed fields, retention, and a training prohibition. Entire profiles are not sent by default.

Subprocessors (planned production)

  • Vercel - Application hosting (planned)
  • Supabase - Postgres, Auth, private Storage (planned)
  • Systeme.io - Early Access and beta email sequences (adapter only; app remains source of truth for product state) (planned)

Data classes

  • catalog: public
  • public_portfolio: public
  • ops_incidents: internal
  • account_identifiers: confidential
  • career_profile: confidential
  • private_evidence: confidential
  • job_analyses: confidential
  • readiness: confidential
  • scenario_results: confidential
  • project_defense: confidential
  • interview_stories: confidential
  • career_advocacy: confidential
  • feedback_360: confidential
  • private_notes: confidential
  • security_logs: restricted
  • credentials: restricted
  • founder_ops: internal
  • ai_usage: internal
  • product_feedback: confidential
  • beta_recruitment: confidential

Your controls

Signed-in users can export data, correct their profile, change portfolio visibility, set aggregate intelligence preference, and delete their account from Settings.

Incidents

Report suspected security issues to the operator using the contact on this site when production launches. The process will be published here; it is not a substitute for a verified incident-response program.