Security
Updated June 29, 2026How we protect your profile, resume, and the work the agent does on your behalf. Security is a feature, not a footnote.
01Encryption in transit
All traffic between you and ApplyLab travels over HTTPS. Your profile, resume, and the agent's work are never sent over an unencrypted connection.
02Where your data lives
Your profile and company dossiers are stored in our database, and your resume in file storage, both run by our infrastructure provider, InsForge. Access is scoped to your account.
03Authentication
Sign-in is delegated to Google or GitHub through InsForge, so we never store a password for you. Sessions use secure, HTTP-only cookies with short-lived tokens that refresh automatically.
04Who processes your data
The agent relies on a small set of providers: InsForge, Google Gemini, Browserbase and Stagehand, Adzuna, Resend, and PostHog. Each receives only what its task requires. See our Privacy policy for the full list and what each one does.
05Reporting an issue
Found a vulnerability or something that looks off? Tell us through our contact page. We review every report in good faith and won't pursue researchers acting responsibly.