Security

Last updated: 14 August 2026

You’re uploading a document with your name, contact details and work history on it. This page explains plainly how that’s handled. We’ve tried to describe what is actually true rather than what sounds most reassuring.

In transit and at rest

Every connection to Offerbench uses HTTPS. Our database is hosted by Neon, with access restricted to our application and encrypted in transit. Passwords are hashed with bcrypt and are never stored in a form we or anyone else could read.

The free resume score never leaves our server

The instant score on our homepage is calculated entirely in our own code. It doesn’t call an AI provider and the file isn’t written to our database. You can use it without an account and without your resume being stored anywhere.

What happens with full scans

A full job-match scan does send your resume text and the job description to Anthropic to extract skills and generate advice. Anthropic processes it to return a response; it is not used to train models. The scan and its report are saved to your account so you can reopen them and compare re-scans.

Who can see your data

Your scans, applications and cover letters are tied to your user account, and every database query is restricted by that account. Another user cannot read, edit or delete your records, including by guessing an identifier.

We don’t sell data, don’t share resumes with employers or recruiters, and don’t use your content for advertising.

Payments

Card details are handled entirely by Stripe and never reach our servers. We store only a Stripe customer identifier and whether your subscription is active.

Deleting your data

Ask via our contact form and we’ll delete your account, scans, applications and generated documents within 30 days, except billing records we’re legally required to keep.

What we don’t claim

Offerbench is a small, independently run product. We don’t hold SOC 2 or ISO 27001 certification, and we’re not going to imply otherwise. What we can tell you is exactly which providers touch your data: Vercel for hosting, Neon for the database, Anthropic for AI analysis, Stripe for payments, and Web3Forms for contact messages.

Reporting a vulnerability

If you find a security problem, please tell us via our contact form before disclosing it publicly. We’ll acknowledge it quickly and won’t pursue anyone who reports an issue in good faith.