Security & Trust
How Job Galaxy protects your data, and who we work with to run the product
Sub-processors
We share data only with the services that run the product — see our Privacy Policy for the full breakdown of what each one sees:
- Supabase — database, authentication, and file storage.
- Stripe — subscription billing; Job Galaxy never sees or stores your card number.
- Resend — transactional email (refund confirmations, support-ticket updates, notifications).
- Google — authentication only, if you choose "Continue with Google."
- Vercel — hosting for this site and its backend functions.
- Nexus and Job Galaxy's own job-collection pipeline — read-only sources for onboarding options and job listings; neither receives your personal data.
How we protect your account
- Passwords are hashed by Supabase Auth — Job Galaxy never stores or sees your plaintext password.
- Sign-in is protected against repeated password-guessing against one account, and account creation is rate-limited per network, to make automated abuse impractical.
- All traffic is encrypted in transit (HTTPS/TLS).
- Database access is enforced by row-level security policies, scoped per user — your account can only ever read or write its own data.
- Billing-sensitive fields (your plan, entitlements) can only be changed by our server, backed by Stripe's own webhook events — never by a client-side request, yours or anyone else's.
- Resumes are stored in a private file bucket and served only through short-lived, signed links generated after we verify who's asking.
- Card details are handled entirely by Stripe on Stripe-hosted pages — they never reach Job Galaxy's own servers.
- Admin actions on user accounts (plan changes, refunds, support responses) are authenticated against a verified admin session and recorded with which admin performed them.
- Job Galaxy doesn't use cookies or third-party tracking/advertising scripts — see our Cookies & local storage policy.
Where we are today
Job Galaxy is a young product built for individual job seekers, not yet an enterprise-sold platform. We haven't pursued formal certifications like SOC 2 or ISO 27001, and we don't yet offer SSO/SAML — we're telling you plainly rather than implying otherwise. We do have an internal incident-response process (who acts, how we contain an issue, and how affected users are notified), though it's an internal document rather than a public runbook. If you have specific security or compliance requirements (for example, evaluating Job Galaxy for a team), email us at hello@jobgalaxy.app and we'll work through them with you directly.
Reporting a security issue
Found something that looks like a security problem? Please email hello@jobgalaxy.app with details — we'll respond and investigate. Please don't test against other users' real accounts or data.