Security
How Raise protects your account and your data.
How your data is stored and protected
- Encrypted in transit. All traffic between your browser and Raise is encrypted (HTTPS, with HSTS).
- Encrypted at rest. Our database provider encrypts all stored data with AES-256.
- Isolated per account. Each account's data is isolated at the database level: the database itself only lets you read and change your own data.
- Private storage. The documents you upload are kept in private storage, reachable only from your account.
- No card data on our servers. Card payments are handled entirely by Stripe: your card details never pass through our servers.
- Secrets stay on our servers. Our secret keys never reach your browser: calls to AI and data providers are made from our servers.
- Checked outgoing requests. Our servers check the addresses they are asked to fetch, to block access to internal networks.
- Hardened by default. We set strict security headers and keep our software dependencies up to date.
Access to your account
You sign in with Google, or with an email address and a password of at least 12 characters, confirmed by a code sent by email. Passwords are stored as one-way hashes by our authentication provider: nobody at Raise can see them. Sign-up and sign-in go through an automated bot check.
Access to administration tools is limited to named people, and is checked by the database itself, not only by the interface.
We will never ask for your password by email. If you sign in with Google, turning on 2-Step Verification on your Google account also protects your Raise account.
Where your data is hosted
Our database and your files are stored in Ireland, in the European Union. The application runs on Vercel, in its Dublin region. Some of our providers are located outside the European Union: see "Who receives it" in our Privacy policy.
How we handle incidents
If we detect a security incident, we act to contain it, investigate it and fix its cause. If it involves personal data and creates a risk for you, we notify the CNIL within 72 hours, as the GDPR requires, and we tell you directly, without undue delay, if the risk is high, with what happened and what you can do. We keep a record of every incident, whether or not it had to be notified.
Reporting a vulnerability
If you find a security issue in Raise, please write to security@raisecareer.ai with a description, the steps to reproduce it and its possible impact. We acknowledge every report within 72 hours and keep you informed until it is fixed. Our contact details are also published in /.well-known/security.txt.
We will not take legal action against research carried out in good faith and within these rules:
- Use your own account. Do not access, change or delete other users' data.
- Do not disrupt the service. No denial-of-service, no mass automated testing.
- No social engineering. No phishing and no physical attacks.
- Give us time. Leave us reasonable time to fix the issue before making it public; we suggest 90 days.
Out of scope: issues in third-party services we use, unless they come from how we configured them. We do not run a paid bug bounty programme at this stage, but we will gladly credit you if you wish.