Draft, pending legal review. This document is an AI-assisted draft and does not yet take effect. It is not legal advice. A qualified attorney should review it before publication, and items marked [CONFIRM] must be finalized.

Security

Last updated June 11, 2026

The short version of how we keep your résumé, profile, and search safe, and how to reach us if you find something.

Our approach

Trust is the product. OyaPilot operates in a category people are right to be wary of, so security and restraint are design goals, not afterthoughts. This page explains, in plain terms, how we protect your information. It is an overview, not a warranty; see our Terms and Privacy Policy.

How we protect your data

  • Encryption. Your data is encrypted in transit (HTTPS/TLS) and at rest with our infrastructure providers.
  • Per-account isolation. Your data is isolated at the database level with row-level security, so one account cannot read another's data, by design rather than by convention.
  • No stored platform passwords. We never ask for or store your passwords or session cookies for third-party sites. Applications are filled in your own browser session (copilot) or submitted only to guest-submittable career-page forms (Autopilot, opt-in).
  • Least privilege. Internal access to systems and data follows the principle of least privilege.
  • Payments. Card payments are handled by Stripe, a PCI-DSS Level 1 provider. We do not store your full card number.

The browser extension

The extension is built on Manifest V3 with narrow host permissions and no remotely-executed code. It receives structured instructions, not arbitrary code, and it fills forms visibly so you stay in control. It never auto-submits unless you explicitly enable Autopilot.

Your data, your control

You can export or delete your résumé and profile data from your account at any time, and request full deletion. See the Privacy Policy for your rights and how to exercise them.

Subprocessors

We rely on a small set of reputable providers (hosting, database, payments, AI, email) listed in our Privacy Policy. We choose providers that meet recognized security standards. We will publish a maintained subprocessor list and any security certifications (for example, SOC 2) as they are obtained.

Responsible disclosure

If you believe you have found a security vulnerability, please report it privately to security@oyapilot.ai. We appreciate good-faith research, will acknowledge your report, and ask that you give us reasonable time to remediate before any public disclosure. Please do not access or modify data that is not yours while testing.

Your part

Security is shared. Use a strong, unique password, keep your devices and browser updated, and be cautious with phishing. Tell us right away if you suspect unauthorized access to your account.

Changes

We will update this page as our practices evolve, with a new "Last updated" date.