Skip to main content

Trust Center

Honesty as architecture

Sezine enforces truthful job applications by design — and we hold our own claims to the same standard. Everything below is split into what our architecture enforces today and what is explicitly roadmap. Nothing on this page is aspirational-worded-as-present.

Enforced today

AI provenance on every output
Every AI-generated artifact carries a visible provenance label — full model pipeline or deterministic template — so users and auditors always know how content was produced. No silent degradation.
Anti-fabrication enforcement
An independent reviewer pass and a separate code-level gate flag any claim in an AI-drafted application that is not supported by the candidate's own source resume. The system is built to refuse embellishment.
No fictional data, enforced by CI
Our continuous-integration pipeline fails any build that imports mock or sample data into employer-facing decision surfaces, and runs verified-secret scanning on every push. A separate pre-launch gate greps the built browser bundles for the actual values of our server secrets before a release is approved.
Server-side secrets, rate-limited APIs
Provider credentials never reach the browser (verified by automated bundle scanning). All AI pipeline endpoints are rate-limited per route, and billing portal access requires verified identity tokens — customer boundaries are enforced server-side.
Explainable matching
Fit scores show their components (keyword coverage, explicit deal-breakers), and AI reviewer critiques are shown in full to the people they affect. No black-box scores anywhere in the product.

Data protection

Personal data (profiles, resumes, applications) is stored in Google Cloud infrastructure and transmitted over TLS. Candidate profiles belong to candidates: employee-visible data is opt-in, and AI features only process the documents a user explicitly submits to them.

Data-deletion and export requests are honored on request via privacy@sezine.com (self-service controls are on the roadmap). A Data Processing Agreement (DPA) for business customers is available on request via the same address.

Sub-processors

ProviderPurpose
Google Firebase / Google CloudApplication database, authentication, hosting infrastructure
VercelApplication hosting and edge delivery
StripePayment processing and subscription billing
AnthropicAI drafting and review (primary model provider)
Mistral AIAI drafting and review (fallback provider)
LightcastSkill and job-title intelligence for resume parsing
OpenWeb Ninja (via RapidAPI)Aggregated public job listings
AdzunaPublic job listings
ResendTransactional email delivery
Google Calendar APIInterview scheduling (user-authorized OAuth)
SlackInternal operational alerting (no user data)

Compliance roadmap

Labeled roadmap because it is roadmap — when these ship, they move to the section above.

SOC 2 Type II ROADMAP
Formal audit program on the compliance roadmap. Our CI-enforced controls (secret scanning, typed builds, least-privilege tokens) are designed to make that audit boring.
EEOC adverse-impact reporting ROADMAP
Structured, auditable screening artifacts exist today (provenance, critiques, scores). Automated Four-Fifths-Rule reporting for employers is roadmap — and will only ever be computed from real pipeline data.
EU AI Act conformity ROADMAP
Our matching already shows its reasoning — the transparency the Act asks of recommender systems. Formal conformity assessment is roadmap as the regulation's timelines mature.
Biometric features (BIPA) ROADMAP
We do not process biometric identifiers today. If voice-identity verification ships, it launches behind explicit per-use consent flows designed for BIPA and GDPR from day one — consent-first is a launch requirement, not a patch.
Security contact
Found a vulnerability, or need our DPA and sub-processor commitments in writing? security@sezine.com — reports are read by the founding team.

IP by Riaan Kleynhans — Human in the Loop. Back to sezine.com