Skip to main content

The security review packLast reviewed Sep 1, 2026

Security and data handling

Everything a review of Career Transition Coverage needs, on one URL you can attach to a ticket. Hey Vitae is operated by Functioning Labs LLC. The Privacy Policy is the authoritative document; this page is the buyer’s summary of the parts that concern a funded program.

The short version

Six answers that end most reviews.

  • You send us no employee data. You buy a block, we mint one single-use code per person, and you hand the codes out yourself.

  • The account is theirs, not yours. Each person redeems on whatever email address they choose.

  • Reporting is aggregate. Outcomes are withheld entirely until at least 5 people have redeemed.

  • No individual is ever reported. Not their applications, not their practice, not where they are in a search.

  • Deletion is theirs to ask for. A covered person can export or delete their account without asking you or us.

  • We train no models on workspace content. Providers process what they receive under their own terms, which we name in full below.

Where it runs

  • Hosting

    Vercel

  • Data

    Supabase

  • Isolation

    Row-level security

The application is hosted on Vercel. Data is stored in Supabase — managed Postgres for records, Supabase Storage for files a person uploads, and Supabase Auth for sign-in.

Both are US-based companies, and both are independently audited to SOC 2 Type II. Neither is a bespoke arrangement built for us — they are the same platforms a great many companies run production on, so a reviewer who has cleared either before has already cleared most of this section.

Processing may occur in the United States and in other countries where they or our other providers operate.

Access to production data inside Functioning Labs is limited to the people who operate the service, and every account that can reach it is protected by multi-factor authentication. Database rows a person owns are separated by row-level security in Postgres, not by a filter in application code, so a query written wrongly returns nothing rather than somebody else’s workspace.

Provider certifications
  • Vercel SOC 2 Type II
  • Supabase SOC 2 Type II
  • Stripe PCI DSS Level 1

Those audits are our providers’, not ours.

Encryption

In transit
HTTPS everywhere, plus Strict-Transport-Security with a two-year max-age, subdomains and preload.
At rest
Database and file storage encrypted by Supabase.
Card data
Never in our systems. Stripe collects it; we receive a plan, a status, an invoice and the last four digits.

A browser that has seen the site once will not make a plaintext request to it again. Connections to the database, to Stripe, to our email provider and to the AI gateway are TLS as well.

Subprocessors

The providers that may process data on our behalf, in the order they touch a request. The Privacy Policy carries the full list and explains international processing; providers may change as the service evolves.

  • Vercel

    All requests

    Application hosting, edge network, and the AI Gateway that routes model requests.

  • Supabase

    All records

    Managed Postgres, authentication, and file storage. Encrypted at rest.

  • Stripe

    Billing

    Payments, invoices and receipts. Card details go to Stripe and never reach us.

  • Postmark

    Email

    Transactional email — sign-in links, receipts, and the mail a covered person's own workspace sends.

  • PostHog

    Opt-in only

    Product analytics, and only for a visitor who has turned optional analytics on.

  • Sentry

    Diagnostics

    Error, trace and performance monitoring for the application itself.

  • OpenAI, Anthropic, Google, Perplexity and Hume

    Per feature

    The models behind resume feedback, job analysis, interview prep and research, and the realtime voice interviewer used only while somebody is in a spoken practice interview.

You transfer no employee data to us

No list upload. No HRIS connection. No eligibility feed. This is the part that shortens most reviews.

Buying coverage does not involve sending us a roster. We mint a block of single-use codes and you hand them out through your own channel — a packet, a mail merge, a graduation folder.

Each person redeems their code on whatever email address they choose, which for most people is a personal one they will still have after the program ends. We learn that a code was redeemed and by which account; we never learn which name on your roster it belonged to, because you never gave us the roster.

The account created that way is the person’s own. It is not provisioned by you, not administered by you, and it outlives the coverage window: when the window ends the extra capacity stops, and their workspace, documents and history remain theirs.

Reporting is aggregate, with a floor under it

What you see

  • Codes issued and redeemed
  • Redemption rate
  • People covered right now
  • Practice interviews handed out and used
  • Whether a given code has been redeemed

What you never see

  • Anyone's applications
  • Anyone's documents
  • Anyone's practice interviews
  • Where a person is in their search
  • Any individual's outcome

Outcomes carry a suppression threshold. Until at least 5 people have redeemed, the outcome line is withheld and says so, rather than printing a number that a small group could be reasoned backwards from. The figure is also self-reported: a person records their own landing, so it under-counts, and it should not be read against your headcount.

The one per-person fact the buyer can see is whether a code has been redeemed, and only because they issued the codes one per person and hold that mapping themselves.

See the actual file

The report is a CSV, generated by the same code for every block. Rather than describe it, here it is, filled in with invented numbers for an organization that does not exist.

sample-program-report.csvDownload
Codes issued
120
Codes redeemed
94
Redemption rate
78%
People covered
91
People who reached a hire
22
Note
Aggregate only…

Deletion

  1. Step 1

    The person requests deletion from their own settings.

  2. Step 2

    A 30-day grace period, canceled by signing in.

  3. Step 3

    Account and content purged, less records we must keep.

Deletion is the individual’s to ask for, and they do not need your permission or ours. From their settings a covered person can also export everything in their account as a file. A deletion request is subject only to records we are required to keep, such as billing history.

A funding organization cannot delete somebody’s account, because it does not own it. Ending or exhausting a block removes the extra capacity and nothing else.

AI and model training

Hey Vitae uses AI for resume feedback, job analysis, interview preparation and practice interviews. A feature sends the prompt and the limited context it needs to the model serving it, through the Vercel AI Gateway or directly to the provider.

We do not use private workspace content to train AI models, and we do not sell personal information. That commitment is in the Terms of Service and the Privacy Policy, not only on this page. Each provider processes what it receives under its own terms; we name them above so a reviewer can check those directly rather than take a summary of them from us.

Something your review needs that is not here

Send us the questionnaire. We would rather answer it than have you guess, and the answers that keep coming up get added to this page.

Purchase termsHow coverage worksPrivacy Policy

Contact us