Security center

Safe account access for website, Chrome, and iPhone.

Alomar Apply is designed so public pages and the Chrome extension never contain Stripe secret keys, OAuth client secrets, webhook signing secrets, or Gmail tokens.

Login and account safety

Production login should use OAuth with signed state, PKCE, secure HttpOnly cookies, account export, and account deletion. Each person should use their own email, license, and Chrome profile. Profile answers such as phone number, years of experience, relocation, work authorization, sponsorship, and optional self-identification choices should be saved per member, not copied from support defaults.

Payments and licenses

Stripe checkout must be created by the backend. Paid licenses should unlock only after the backend verifies Stripe webhook signatures and stores the subscription status.

Chrome extension

The extension uses limited host access for supported job sites and alomarapply.com, local storage for user-controlled settings, and notifications only for account/run updates. It does not request browser history permission. Public packages should not contain server secrets, payment keys, raw private license lists, or support-only profile defaults.

iPhone web app

iPhone alerts are opt-in and require explicit notification permission. Email, SMS, Gmail, and outreach features must remain opt-in and must not send silently.

Support

Report security, privacy, or account issues at support@alomarmarketing.com.