ApplyOnce
Security and privacy

Trust is part of the product, not a footer link.

ApplyOnce is designed around minimum necessary data, explicit consent, private documents, and clear recovery when something changes.

A measurable baseline, not an absolute promise.This public beta uses Clerk authentication, server-side authorization, Neon/Postgres, private Vercel Blob storage, validation, audit events, and explicit integration boundaries. Production operators still need monitoring, incident response, retention, and credential reviews.
The control model

Every sensitive step has a visible owner.

Citizens decide what to share. Partners declare why they need it. ApplyOnce keeps the handoff reviewable.

Citizen control

People see the requested fields, purpose, source, and destination before an application is shared.

Private documents

Documents use private storage, short-lived access, file type limits, and ownership checks.

Tenant isolation

Partner records are organization-scoped. Client-supplied organization IDs are never trusted for access.

Official rails only

ApplyOnce does not scrape protected portals, bypass CAPTCHA, or store face, fingerprint, or iris templates.

Auditable consent

Consent hashes, revocations, status changes, and important actions are recorded as durable events.

Honest state

Sandbox, approval-pending, unavailable, degraded, and connected states remain visibly different to users.

What we do not do

No unofficial shortcuts with citizen identity.

Official identity and document providers remain the source of truth. ApplyOnce stores the minimum claim or reference needed for a declared application purpose.

No protected-portal scraping No CAPTCHA bypass No silent submission No biometric vault