Trust, security, and governance
Audited claims. Honest boundaries.
Everything on this page was verified against the actual codebase before it was written here. Where the platform falls short, that is stated too, with the fix on a public list. You do not have to take any of it on faith: the code is public.
The whole thing in five sentences
Participants own their accounts and control what organizations see. Staff dashboards read progress signals only -- never transcripts, never private words -- and that boundary is enforced in the database queries, not in a policy PDF. Your data stays until you decide otherwise -- delete it or download all of it, both self-service. There is no advertising, no data brokerage, and no resale. The entire codebase is public, so your security reviewer can check every sentence on this page.
Open what you care about
The consent boundary, verified What staff can see, what they cannot, and what happens the moment consent is revoked.
- One data path. Every staff and organization dashboard reads through a single query. That query returns: name, stage, application and practice counts, and yes/no progress flags. It cannot return resume text, disclosure drafts, intake answers, or coaching conversations, because it never selects those fields.
- Coaching transcripts are marked never-exposed at the database level. The only code that can read them is the participant's own coach session.
- Consent is granted by the participant, in their own settings, and revocation is immediate. The staff cohort query checks consent status at read time -- a participant who revokes disappears from the dashboard on the next load, counted anonymously, never named.
- The account belongs to the person. Every piece of participant work is keyed to the person's account, not the organization. No organization endpoint can delete or transfer a participant's data. If someone leaves a program, their work goes with them.
What we store, and what we do not claim An honest inventory. We store your work so you can keep it -- and you can delete it.
- What is stored: your resume and career-report content, your saved artifacts (tailored resumes, disclosure plans, cover letters, interview prep), your coaching conversations, your applications, and your consent history. It is stored so your work is still there next session -- that is the product.
- Delete it, or take it with you. Both are self-service in Settings. Delete removes your content -- resumes, artifacts, applications, coaching history, profile -- from the platform's database. Export downloads all of it as a single file so your work is yours to keep. Deletion and export are equals here: whatever we store, you can remove, and whatever we store, you can take.
- Every AI call is metered, costed, and attributed to the person who made it, and coaching has per-person daily limits. That is what makes "free for the person" a sustainable sentence, and it is how an organization sees real per-person usage instead of estimates. It is usage metadata -- who used the AI and what it cost -- never the content of what was said.
- Analytics, stated precisely: no advertising trackers, no ad-tech, no data brokerage, no resale. The platform uses aggregate, cookieless product analytics from its hosting provider to see what is slow or broken -- and none at all on the shared-tablet flow built for facility use.
Security posture What a hostile reviewer finds: parameterized queries, scoped access, hashed tokens, rate limits, public code.
- Every data access is ownership-scoped in SQL. Participant records are only readable with the participant's own authenticated ID; organization records are double-filtered by organization, derived server-side, never trusted from the client.
- All database access is parameterized. No string-built SQL. No raw HTML injection surfaces in the apps.
- Invite links and reset tokens are random, salted, hashed at rest, and expire. A participant already connected to one organization cannot be silently claimed by another. Password hashing is bcrypt at cost 12, and reset flows do not reveal whether an account exists.
- AI endpoints are rate-limited with per-tier and per-person limits, pooled sensibly for shared classroom networks, so abuse cannot burn the platform down.
- Secrets are kept out of the repository and an automated secret scanner runs on every code push.
- Security headers -- HSTS, frame denial, content-type protection, CSP -- are set globally.
- The codebase is public. github.com/Steel-Man-Resumes/smr-crucible. An independent review found the issues you would expect a young platform to have; they are on the build list, and the serious ones get fixed first. That is how this works: found, listed, fixed, in the open.
Operator access, disclosed Yes, the platform operator can assist inside an account. It is time-limited, audited, and the participant is told.
Sometimes helping a person means looking at what they see. The platform has a break-glass assist mode for the operator. We disclose it because you should not have to discover it:
- It requires the operator tier and is checked at issue and at use.
- Sessions are short -- minutes, not days -- and signed, and view mode is enforced read-only at the network edge.
- Every session is logged to an audit table, and the participant's own coach chat is notified when a session ends.
Most platforms have some version of this and do not tell you. We would rather tell you.
Accessibility Built for cracked phones and library computers. Audited, honest about the gaps, fixing them in order.
- This site passes automated WCAG 2.1 AA checks on every page: contrast, labels, structure, zoom never blocked.
- The platform's design system targets WCAG AA on purpose: 18px minimum body text, 48px touch targets, labeled form fields with announced errors, reduced-motion support, and no zoom blocking anywhere.
- Known gaps exist and are listed: an independent audit found keyboard and screen-reader issues in several dialogs and some small low-contrast labels in the apps. They are ranked on the public build list and get fixed in order of user impact.
- If something blocks you, tell the founder directly -- every contact route is here -- and it moves to the front of the line.
What we do not claim The boundaries, stated plainly, because institutions state their boundaries.
- Not legal advice. The disclosure planner is coaching for a hard conversation. It says so in the product, and it means it.
- Not a HIPAA covered entity. This platform handles employment history, not medical records, and does not claim HIPAA compliance.
- No SOC 2 audit has been completed. A one-person operation tells you that instead of implying otherwise. What you can do today: read every line of the code, bring your security reviewer to a call, or run your own instance on your own infrastructure.
- Not perfect. The independent review that produced this page found real items. They are tracked and fixed in severity order. Judge the platform by that loop, not by a badge.
Governance, in one paragraph
Steel Man Resumes is built and operated by Troy Carr, who is justice-impacted himself and built the platform because he needed it first. Security reports, compliance questions, and hard conversations go straight to the founder: troyrichardcarr@gmail.com. Bring your compliance person to a call -- that conversation is welcome, not dodged. Book it.
