Security
Boundaries you can inspect.
Role Rover is designed to keep core job-search data local, require review before consequential actions, and fail closed when a page or input no longer matches what you reviewed.
No Role Rover account or backend
Role Rover does not operate a user account system, profile API, hosted application database, or publisher analytics service. Sensitive extension data lives in browser-managed storage and inherits the security of the local operating-system account and browser profile.
Optional-provider boundaries
Chrome built-in AI and local Ollama can process bounded data locally. Claude and optional APIs can transmit disclosed data only after setup and consent. Provider-side handling follows the provider and user's account terms; Role Rover cannot change those policies. See the privacy policy's transfer details.
Application safety boundary
Role Rover inspects visible fields on supported HTTPS application pages, excludes protected or unsupported questions from automatic proposals, and checks that a reviewed field has not changed before filling. It does not contain a final-submit action and never clicks Submit.
Backups and credentials
Password-protected backups use AES-256-GCM with a password-derived key; plain JSON is an explicit alternative. USAJOBS and Apify credentials are excluded from backups and diagnostics. Live extension storage is not independently encrypted, so device and browser-profile security remain important.
Report a vulnerability
Email security@getrolerover.com with a concise description, affected version, and safe reproduction steps. Do not send real résumé data, credentials, cookies, CAPTCHA content, or exploit other people's data. We will acknowledge useful reports when practical but do not promise a fixed response time.
This page describes engineering boundaries; it is not a claim of certification, complete security, or legal compliance.