Your career data, secured and never sold.

STEADION is built so the most personal data you own, your career, stays yours. Here is exactly what the system does and where it stands.

Commitments to you

Your data is encrypted in transit (TLS) between you, STEADION, and our providers.

Backed by: All endpoints served over HTTPS/TLS; all provider traffic originates server-side over TLS (Security Baseline, network path).

Your data is never sold or shared with third parties for their own purposes.

Backed by: Contractual non-sale commitment in the Privacy Policy; no data-broker integrations exist in the codebase (Absolute Prohibition #3).

AI use of your data is consent-gated, per class, and revocable.

Backed by: ai_router CR-13 consent check before every call against user_consents; Settings -> AI Privacy revocation (F-01).

You can export all of your data and permanently delete your account.

Backed by: GDPR Art. 20 export endpoint + account deletion with 90-day grace and full purge (F-06 / F-07).

AI output is grounded in your real experience and never fabricated.

Backed by: Rule 2 prompt grounding enforced in ai_router; no fabrication capability (Absolute Prohibition #4).

Your career data is never used to train provider foundation models.

Backed by: Provider enterprise/API tiers with no-training defaults; DPA register (CR-9, ship-gate before production).

Where STEADION stands on compliance

Aligned means practices meet the framework today. Target means STEADION is working toward formal certification and never claims a certification it does not hold.

GDPR (EU)Aligned
CCPA (California)Aligned
SOC 2 Type IITarget 2027
ISO/IEC 27001Target 2027

Posture last updated 2026-06-29.

Take control of your career, on your terms.

Join the beta waitlist