Skip to content

Last updated 23 September 2026

Security and data controls

Practical safeguards for your account and job-search information. We describe our controls and their limits rather than claiming that any website is unhackable.

Your account and documents

Private workspace records use account ownership checks and database row-level security. Internal billing and usage records are changed by server operations, not by a browser choosing its own plan. Public government register information is intentionally available where a feature needs it; that does not make private applicant records public.

Uploaded documents use private storage with owner-scoped access. A document-open request creates a short-lived link, normally valid for 60 seconds. Anyone you share that link with may use it until it expires. Downloaded copies remain on the receiving device.

Authenticator-app two-step verification is being prepared and new enrolment is not available yet. Account and data shows the controls currently available to your account. We do not claim that all database or document access currently requires a second factor. Keep a unique password and sign out on shared devices. Account export and deletion require a recent sign-in. Deletion freezes new account writes while active records and documents are removed; legal payment records and provider backups can have separate retention periods.

Payments and limits

Card entry takes place in Stripe-hosted Checkout. Milo keeps the references and payment status needed to manage your purchase, not your full card number. Signed payment events and server checks control paid access. A success-page URL, browser counter or locally edited plan label cannot activate an entitlement.

Checker limits are counted on the server for the authenticated account. Retries use request identifiers so a duplicate request need not consume the allowance twice. Short-term request and service-capacity controls also apply.

Monthly plans stay closed until billing and included services are ready. The plan comparison identifies features in private testing.

Research, applications and AI

Company research and supported job imports go through authenticated server requests. Fetches restrict destinations, redirects, time and response size, and block private network addresses. A website that cannot be safely imported can be supplied as pasted text. The browser does not send requests through public CORS proxies.

Milo does not ask for or store employer ATS passwords. Automatic employer submission is not active. Review application materials and submit to the employer yourself; preparing a file or queue item is not proof of submission.

The private application inbox receives messages sent to an assigned Milo application address. This is separate from connecting your personal Gmail or Outlook inbox; Milo does not need those inbox passwords. The feature still processes incoming email, so avoid forwarding unrelated sensitive messages.

AI requests run through the server with account and usage checks. Review and remove unnecessary personal information before sending. Requested AI content is sent to OpenAI through Milo’s server; do not assume contact details or identifying work history are automatically removed. AI output cannot change your plan or send an application merely by asking for that action.

Providers and retention

We use HTTPS for browser-to-service connections and rely on our hosting, database and payment providers for infrastructure encryption and protection. These controls do not provide end-to-end encryption: authorised service operators and processors may need access to provide and support the service.

Core processors include IONOS, Supabase, Stripe, OpenAI for requested AI tasks, Resend for the application inbox, and Google Workspace for support correspondence. Optional Google Analytics loads only after consent. Fonts are served with the site. Read the privacy notice for purposes, retention, provider links and international-processing information.

Checker request metadata is retained for up to 30 days; raw checker text is processed in memory rather than saved as a document. Other workspace, payment and email records follow their own retention rules. There is no claim that every category is deleted after 30 days.

Independent assurance

We do not currently publish an independently verified penetration-test report, SOC 2 certification, Cyber Essentials certification or scanner grade for Milo. Provider certifications are not certifications of our application. Cloudflare protection and account-level provider settings are not claimed here unless their deployment has been verified.

Security changes are tested before release, but a passed test cannot prove that every vulnerability has been removed. We do not claim that Milo is more secure than a named competitor without comparable independent evidence.

Report a concern

Email support@milojobs.com with the subject “Security report”, the affected page, approximate time and steps to reproduce. Use your own account and the least data necessary to explain the issue. Do not access another person’s data, send credentials, disrupt service or run bulk scans without written agreement.

If you encounter personal information unexpectedly, stop testing and tell us how it appeared. Please allow time to investigate before publishing exploit details. No bounty or response deadline is promised. Our machine-readable contact is at security.txt.

If personal data is affected

We assess incidents and take steps to contain them. A qualifying personal data breach is reported to the ICO without undue delay and, where feasible, within 72 hours after becoming aware of it. Where it is likely to create a high risk to people, we notify those affected without undue delay. Not every technical incident meets those reporting thresholds.