Skip to content
TruApply

Security

How to report a problem, and how your data is looked after.

Last updated

Report a problem

Found something that looks like a security issue? Email neeraj@neerajpal.dev with what you found and the steps to reproduce it. You’ll get a reply as soon as possible, usually within a few days, and a note when it’s fixed.

While you look, please don’t access or change other people’s data, don’t run tests that slow the service down for others, and give a fair chance to fix the issue before sharing it publicly. Good-faith reports are welcome and appreciated.

The same contact is published in /.well-known/security.txt.

How this site is built

  • Pages are static files served over HTTPS by Cloudflare.
  • A strict Content Security Policy allows only this site’s own scripts, styles, fonts and images. There are no third-party scripts, cookies or analytics.
  • The waitlist form checks every email on the server, ignores bots that fill a hidden field, caps the size of what it accepts, and stores only your email, the optional role, the form used and the time.
  • A repeat signup gets the same answer as a new one, so the form never reveals whether an address is already on the list.

How the product treats your data

  • Your resume and facts are private to your account and are never sold.
  • Nothing is sent to an employer without your approval.
  • A cost guard caps AI usage, so AI work pauses at the limit instead of running on.

The privacy policy covers what’s collected and how to have it deleted.