Security & data handling
Last updated September 29, 2026
This page is deliberately specific rather than a wall of badges. We are not SOC 2 or ISO 27001 certified — we're a small, early-stage product, and we'd rather tell you exactly what is and isn't true today than display a certification we don't hold. Everything below is a real, checkable fact about how the system is built.
Resume handling
A resume you upload is parsed in memory, sent once to our AI provider to generate the anonymised brief, and then discarded. There is no database table, column, or file-storage bucket anywhere in the system that a resume file is ever written to. This isn't a policy we follow — it's a structural fact about the schema: the column doesn't exist, so there is nowhere for a resume to end up even by accident.
Firm data isolation
Every database query that reads or writes firm-scoped data (briefs, clients, templates) is filtered by the requesting user's own firm ID, derived server-side from their session — never from a value the client sends. A firm cannot read another firm's briefs by guessing or manipulating an ID, because the query itself never runs without the firm-ID filter attached.
Authentication & access control
- Passwords are hashed with scrypt (a memory-hard, purpose-built password-hashing algorithm) and a unique random salt per password — never stored in plaintext or in any reversible form.
- Sessions use a random 256-bit token stored in an
httpOnly,secure,SameSite=Laxcookie — inaccessible to page scripts, so a cross-site scripting bug elsewhere can't be used to steal a session. - Three roles (owner, admin, member) gate what each teammate can do — billing, team management and retention settings are owner-only; day-to-day work is available to every role.
- An invited teammate's account cannot be logged into before they accept the invite — the placeholder credential set on invite creation is not a usable password.
Encryption
All traffic to and from MagflowAI is encrypted in transit (HTTPS/TLS). Data at rest is encrypted by our database provider, Neon, using their standard managed-Postgres encryption.
Payment data
We never receive, process or store your card number. Checkout happens entirely on Stripe's own hosted page; we only ever receive a customer ID and a subscription status back. Stripe is a PCI-DSS Level 1 certified payment processor — the highest level of certification in that standard.
Infrastructure
| Provider | Role |
|---|---|
| Vercel | Application hosting and edge network |
| Neon | Managed Postgres database (primary region: AWS us-east-1) |
| Stripe | Payment processing, PCI-DSS Level 1 certified |
| Resend | Transactional email delivery |
| MailerLite | Marketing email — trial welcome sequence and requested-resource delivery |
| Our AI processing provider | AI text generation for brief anonymisation, under a Data Processing Addendum executed on our account — see our Privacy Policy for the international-transfer detail on this one specifically |
Data retention & deletion
Every firm sets its own brief-retention window (default 90 days) in Settings. An automated job runs daily and permanently deletes anything past that window — retention isn't a policy on paper, it runs. Full table of what's retained and for how long is in Section 8 of our Privacy Policy.
Incident response
If we become aware of a security incident affecting your data, we will notify affected firm owners by email without undue delay, and within 72 hours of becoming aware of it where required by applicable law. We do not currently have a public bug bounty program, but we take reports seriously — see below.