Amazon Web Services
Private file storage, application infrastructure, and transactional email delivery.
Security and data handling
Resumes contain contact details and career history. This page explains where that information goes, which controls are implemented, and where the limits are.
Control review: July 19, 2026
Scoritly does not claim end-to-end encryption, zero data retention, or a security certification it has not earned. No online service is completely secure. The controls below describe the current product; the Privacy Policy remains the full data-practices notice.
01
Pasted resume and job text is compared in your browser. Scoritly receives only text-free daily aggregate counters for completed previews, share actions, and signup-button clicks. Sharing sends only the public checker link and generic introductory text - never the pasted text or result.
02
After sign-in, PDF, DOCX, and TXT files up to 5MB use a five-minute upload link. The server verifies the object metadata and extracts text before saving the resume to your account.
03
Scoritly sends the extracted resume text and the relevant job posting to Anthropic's commercial Claude API for scoring and drafting. Source documents are treated as untrusted data, not model instructions.
04
Downloads require your authenticated account and use five-minute links. Document deletion removes the stored object before its database record; account deletion also cancels recurring billing before the account record is removed.
Resume, scan, cover-letter, tracker, and download routes check the signed-in user and scope records to that account.
Upload type, extension, declared size, stored size, content type, extracted length, and parser limits are checked. Supported uploads are capped at 5MB.
Uploaded and generated files live in private cloud storage, encrypted in transit and at rest, with public access blocked. Temporary upload and download links expire after five minutes.
Passwords are hashed with bcrypt before storage. Sign-in requires a verified email, and authenticated sessions use signed tokens.
Resume and job text is labeled as untrusted reference data. Embedded role changes, prompt requests, markup, or instructions are not treated as application commands.
Model responses are parsed into bounded structures. Resume edits must target existing text and preserve protected facts such as numbers, credentials, contact details, and source evidence.
Stripe handles payment-card data. Scoritly stores only limited customer, subscription, and purchase metadata needed to provide and support paid access.
If object-storage cleanup fails, Scoritly keeps the database record so the deletion can be retried instead of silently losing track of a stored file.
Private file storage, application infrastructure, and transactional email delivery.
Resume and job text for requested AI analysis. Anthropic says commercial API inputs and outputs are not used for model training by default and describes its standard API retention.
Checkout, payment-card handling, invoices, subscription management, and refunds.
Google Analytics and Meta measurement load according to the cookie choice described in the Privacy Policy. Resume and job text is not sent as analytics event data.
Questions or reports
Email contact@scoritly.com. Describe the issue without attaching a resume, password, API key, payment card number, or other sensitive data.