Security and privacy, explained plainly.
ReProfile does one thing with a candidate’s CV: reformats it into your agency’s template. It is not a candidate database and it is not an archive — uploads are processed in memory, and the completed document is automatically deleted from active storage within 20 minutes of completion. This page explains the controls behind that, in plain English.
Clear boundaries for candidate information.
ReProfile keeps as little as possible, for as short a time as possible, and is straightforward about the providers that run the service.
Built for one purpose
Candidate CVs are used to provide, secure and support the reformatting your agency requests, and to meet legal obligations — nothing more. Never sold, never used for advertising, never used to train AI models.
Nothing builds up
ReProfile never accumulates a library of candidate CVs. Uploads are processed in memory and completed documents clear from active storage automatically within 20 minutes.
Your organisation controls access
Every user has an individual account. Completed documents are available through the service only to active members of your organisation, enforced by database row-level security, and only during the short download window. You control who your members are.
Protected in transit, at rest and by isolation
All data flows use TLS. Stored data is encrypted at rest. ReProfile runs on dedicated infrastructure — a separate database, authentication system and credentials from any other product operated by SpokeCV Pty Ltd.
What happens to a CV.
From upload to deletion, each stage has one job and a defined end point.
- 01
Upload
The CV is uploaded over an encrypted connection and processed entirely in memory. It is never saved to ReProfile’s file storage, and the original filename is never stored.
- 02
Reformat
Text extracted from the CV is sent to Anthropic’s commercial API in the United States, which rebuilds it into your template’s structure. This content is not used to train Anthropic’s models, and ReProfile does not opt in to training.
- 03
Download
The completed document is stored encrypted at rest for a short download window. In ordinary operation it is retrieved by the consultant who submitted it; during the window it is available to active members of your organisation, whose membership your agency controls.
- 04
Delete
Within 20 minutes of completion, the completed document is automatically deleted from active application storage. No manual step, no retention setting — deletion is the default. Residual encrypted copies that fall within an infrastructure provider’s backups expire on that provider’s normal cycle; full detail is in the Privacy Policy.
What remains
Operational records: organisation and user identifiers, template, timestamps, job state, file size, processing time and a sanitised error code — and, where a consultant enters them, six placement-detail fields: position title, notice period, availability, charge rate, pre-booked leave and client company. The CV body, the original filename and the completed document are not retained beyond the windows above.
Practical controls around a short-lived workflow.
Access controls, data minimisation and operational discipline, matched to a service where candidate content barely rests.
Identity and access
- An individual account for every user.
- Organisation-scoped access enforced by database row-level security.
- Administrative and service credentials restricted and held in provider secret-management systems.
- Infrastructure fully separate from any other product operated by SpokeCV Pty Ltd.
Data protection
- TLS for all data in transit.
- Encryption at rest across stored data.
- A deliberately short completed-document download window.
- No file or object storage of uploaded CVs.
Operational safeguards
- Error messages are sanitised at source — operational codes, not candidate content.
- Request and response bodies carrying CV content are excluded from application logs.
- Dependency and secret scanning, security updates and secure-development review.
- Incident assessment and response procedures.
Where the service runs — including the one step outside Australia.
Three providers run the core service. Two are configured in Sydney; the AI reformatting step is performed by Anthropic in the United States, and here is exactly what that involves.
Supabase
Sydney, AustraliaDatabase, authentication and serverless functions. Holds account data, operational records, placement-detail fields and the encrypted completed document during its short download window.
Vercel
Sydney, AustraliaWeb application hosting and the reformatting worker. Processes uploaded content transiently, in memory, to provide the service.
Anthropic
United StatesThe AI reformatting step. Extracted CV text is processed by Anthropic’s commercial API. It is not used to train Anthropic’s models, and Anthropic ordinarily deletes commercial API inputs and outputs within 30 days. Anthropic holds SOC 2 Type II, ISO/IEC 27001:2022 and ISO/IEC 42001:2023 certifications, published at trust.anthropic.com — these are Anthropic’s certifications, applying to Anthropic’s platform.
No support tool displays candidate CV content.
ReProfile has no support dashboard, admin screen or internal tool that displays candidate CV content. Support and troubleshooting work from operational records — job state, timestamps, error codes — not from documents.
Authorised personnel may access a completed document during its short download window only where reasonably necessary for support, security, legal compliance or service operation, and subject to confidentiality obligations. This is not part of ordinary processing — and once the window closes, the document has already been deleted from active storage.
What agencies and authorised users need to do.
- Give each user their own account, protect login details, and remove access promptly when someone is no longer authorised.
- Make sure candidates have received any notice required for the providers and overseas processing described on this page.
- Only include sensitive information where it is genuinely needed for the placement and your agency is authorised to submit it.
- Review every completed document before sending it on — final approval always sits with the consultant.
- Download and file what you need: ReProfile is not an archive, and the download window is short.
- Tell us promptly about any suspected unauthorised access or security issue.
Questions from your agency or procurement team?
Security questionnaires, privacy questions, procurement detail and DPA requests all go to the monitored ReProfile address — answered by the founder, not a ticket queue. If you need to share documents as part of a support request, contact us first and we’ll agree a secure method.