Security

How we protect your career record

Your record holds years of work, so we treat it with care. This page explains where it is stored, who can see it and how to tell us about a security problem.

Where your data is stored

Your career record, account and uploaded files are stored in Supabase in London (eu-west-2). The server code that reads and writes them also runs in London.

Some optional features use services outside the United Kingdom, such as AI processing and payments. The privacy notice explains exactly what is sent and when.

Encryption

Every connection to OTO uses HTTPS. Stored data, including uploaded files, is encrypted at rest by our database and storage provider.

Credentials for connected Google and Microsoft accounts are encrypted again with a key held outside the database, and only server-side code can use them.

Who can see what

Every table that holds account data uses row-level security, so the database itself only returns the records an account is allowed to see.

Your profile starts private. Uploaded CVs, pictures and videos sit in private storage and are only reachable through time-limited links issued to you or, for a shared CV page, to visitors your sharing settings allow.

Administrative keys are used only on our servers and never sent to your browser.

Your account

Passwords are never stored in plain text. Sign-in and sign-up are protected against automated abuse, and inactive sessions end automatically.

You can export your data or delete your account from Settings. Deletion removes your data from live systems within 24 hours and from backups within 30 days.

Connected accounts and AI

Google and Microsoft connections are optional and ask for each permission separately. Disconnecting removes the stored credentials and imported records.

Connected calendar, email and file records are not sent to AI providers. Documents you choose to analyse and coaching questions you submit are sent only for that task and are not used to train general-purpose AI models.

Payments

Payments are handled by Stripe. Card details go directly to Stripe and never reach our servers.

Backups and resilience

The database is backed up daily and backups are kept for no more than 30 days.

Reporting a security problem

If you think you have found a vulnerability, email security@otovios.com with enough detail for us to reproduce it. We will acknowledge your report and keep you informed while we fix it.

Please test only against your own account, do not access or change anyone else's data, and do not run tests that disrupt the service for others. Give us a reasonable chance to fix the problem before you share it.

Our contact details are also published in the standard security.txt file. If your account has been compromised, change your password and write to the same address.