Skip to main content

Last updated September 21, 2026

Stored in the United States

Hosted in US data centres, with data and backups encrypted at rest (AES-256) and all traffic over TLS.

Owner-only access

Every record is locked to the student who created it. Files are private and read only through short-lived signed links.

Schools see numbers, not work

Institutions get aggregate usage reports. No student's résumé, answers or account is ever shared with the school.

Students control deletion

Export everything, delete anything, turn on automatic deletion after 3, 6 or 12 months, or delete the account.

No sale, no ads, no training

We never sell data, never show ads, and never use student content to train AI models.

Students stay in charge

AI drafts; the student reviews and decides. Nothing is invented, and no automated decision is made about a student.

Data we handle

Students create their own accounts and add their own content. Institutions do not need to send us any student records for the service to work.

Categories of data OfferReady AI handles
CategoryExamplesPurposeRetention
AccountName, email, sign-inRun the account and campus seatUntil the account is deleted
Career contentRésumés, job postings, analyses, cover letters, interview prep, STAR stories, tracker entriesProvide the features the student usesUntil deleted by the student, or automatically after the window they choose
Voice answers (optional)Mock-interview audioTranscribe the answerUsed only for transcription; never played back or linked to the profile
Campus seatInstitution, seat status, licence datesGrant and report on accessFor the licence term
UsageFeature use, device and browser, error logsSecurity, support, aggregate reportingRolling platform retention; logs exclude résumé content

Security

OfferReady runs on a cloud platform that is independently audited to SOC 2 Type II and ISO 27001, with US data hosting, AES-256 encryption at rest for data and backups, TLS 1.2+ in transit, automated backups and a formal incident-response programme. The platform's SOC 2 report can be requested under NDA.

Controls in the OfferReady application:

  • Row-level access rules on every data type: students can read and change only their own records.
  • Private file storage; files are read server-side through signed links that expire after 5 minutes.
  • All AI prompts and model calls run in authenticated server functions; nothing sensitive ships in the browser app.
  • API keys and payment credentials are stored as server-side secrets, never in source code.
  • Every server function verifies the caller; administrator-only functions check the admin role.
  • Automated security scanning of access rules, server functions, secrets and dependencies before release.
  • Server logs capture errors only — never résumé text or answers.
  • Institution records and seat counts are readable only by OfferReady's administrator.

FERPA & student privacy

  • What the institution receives: aggregate reports only — seats activated, résumés tailored, cover letters, match analyses, mock interviews completed, and outcomes students chose to record. Counts below 5 are suppressed.
  • What it never receives: any student's documents, answers, scores or account access.
  • If you share student records with us (for example an eligibility list), we act as a "school official" under FERPA (34 CFR § 99.31(a)(1)(i)(B)): we use the data only to provide the service to you, under your direction, do not re-disclose it, and return or delete it at the end of the agreement.
  • We will sign your institution's FERPA or data-security addendum.
  • When a licence ends, students keep their accounts on the Free plan, or — if your agreement requires it — we delete campus-seated accounts' content on a date you set, after giving students notice to export.

Full detail is in our Privacy Policy.

Accessibility

We design and test to WCAG 2.1 Level AA — the standard in the ADA Title II rule and in Section 508. Our Accessibility Statement lists how we test, current known limitations and how to request an accommodation. An Accessibility Conformance Report (VPAT® 2.5, WCAG edition) is available to institutions on request.

AI use

  • AI is used to parse résumés, compare them with a job posting, suggest rewrites, draft cover letters and run interview practice.
  • Every output is a draft the student reviews and edits. OfferReady does not make or support decisions about admissions, grades, discipline or employment.
  • Prompts forbid inventing experience or inferring protected characteristics. Match scores are labelled as estimates.
  • OfferReady does not use student content to train AI models, and our platform provider's data processing agreement limits its use of personal data to providing the service.

See the AI Transparency Policy.

Incident response

If we confirm a security incident affecting student personal information, we notify the affected institution without undue delay — and within the notice period in our agreement with you — with what happened, what data was involved and what we are doing about it. We notify affected individuals and regulators within the time limits the law sets.

Reviews & documents

We will complete your institution's security, privacy and accessibility review. Available on request:

  • HECVAT 4 (EDUCAUSE Higher Education Community Vendor Assessment Toolkit)
  • Accessibility Conformance Report (VPAT® 2.5, WCAG 2.1 edition)
  • Data flow diagram and our sub-processor list
  • Signature of your FERPA / data-security addendum
  • State cloud-security program assessments, such as TX-RAMP in Texas
  • W-9 and sole-source letter

Email support@offerreadyai.app with "Institutional security review" in the subject line.