Built like it's your career on the line. Because it is.
Every control on this page is live today — not a roadmap item wearing present tense — and each one names what it does not cover.
Your data is yours.
Export what you've given us, any time, from Data & privacy in your account — no support ticket, no waiting. Request deletion and it starts as soon as you confirm, completing within the window the product shows you. Both are built into the product, on every plan, ungated. A few account-level stores sit outside the export, and two records survive deletion by design; the data page names every one of them.
Hard tenant isolation.
Every tenant-owned table carries your tenant identity, and the database enforces row-level security on it — isolation is a property of the schema, not of application code remembering to filter. A small number of account-level stores are global by design: beta access and organization membership. They hold no job-search content.
Encryption in transit and at rest.
TLS in transit. Your resume text, personal details, email bodies, calendar entries and compensation records are envelope-encrypted at rest with per-tenant data keys anchored to a cloud KMS — the root key never sits in a config file. Other personal stores hold structured records rather than free text, and some free-text fields are still stored unencrypted. The register names each one and the data page lists them.
An audit trail that can't be quietly edited.
Every action Falcyn takes in your account writes an append-only, hash-chained audit entry before the action completes. You can read your own activity feed in the app.
You execute, Falcyn prepares.
Falcyn never submits applications, sends messages, or takes any third-party action for you. Everything it drafts waits in your review queue until you act — that boundary is enforced in the architecture, not just the copy.
Your documents don't train models.
We call commercial model APIs under terms that exclude training on your content, and we never use your resumes, letters, or notes to build models ourselves.
Where a control has an exception, it is named above and counted on the data page. On formal attestations: we build to recognized control frameworks from day one, and we'll only ever claim an audit result after an auditor issues it. Questions about our practices? security@falcyn.ai.