Security
How to report a problem, and how your data is looked after.
Last updated
Report a problem
Found something that looks like a security issue? Email neeraj@neerajpal.dev with what you found and the steps to reproduce it. You’ll get a reply as soon as possible, usually within a few days, and a note when it’s fixed.
While you look, please don’t access or change other people’s data, don’t run tests that slow the service down for others, and give a fair chance to fix the issue before sharing it publicly. Good-faith reports are welcome and appreciated.
The same contact is published in /.well-known/security.txt.
How this site is built
- Pages are static files served over HTTPS by Cloudflare.
- A strict Content Security Policy allows only this site’s own scripts, styles, fonts and images. There are no third-party scripts, cookies or analytics.
- The waitlist form checks every email on the server, ignores bots that fill a hidden field, caps the size of what it accepts, and stores only your email, the optional role, the form used and the time.
- A repeat signup gets the same answer as a new one, so the form never reveals whether an address is already on the list.
How the product treats your data
- Your resume and facts are private to your account and are never sold.
- Nothing is sent to an employer without your approval.
- A cost guard caps AI usage, so AI work pauses at the limit instead of running on.
The privacy policy covers what’s collected and how to have it deleted.