Where your data lives
- The platform's database is hosted by Supabase in Australia (Sydney region). Transfers are protected by the Standard Contractual Clauses in Supabase's Data Processing Agreement.
- The website is served through Cloudflare's global network.
- Email is sent through Resend. Error reports go to Sentry (EU region).
- The full list of service providers is in our Privacy Policy.
Encryption
- All traffic to the website and platform uses HTTPS (TLS), with HSTS enforced.
- Data is encrypted at rest by our database provider.
- Direct database connections require encryption and are limited to named administrator machines.
Accounts and access
- Passwords are checked against known data breaches and stored only as secure hashes.
- Two-factor authentication (authenticator app) is available to every account.
- Sign-up, login and password reset are protected by a bot check.
- Sessions expire after inactivity, and changing an email address or password requires confirming the current password.
- Every table in the database has row-level security: each person can only reach their own records, and staff access is checked on the server for every request.
- Actions by our staff and administrators are recorded in an audit log.
Application security
- A strict Content Security Policy, clickjacking protection and other security headers are enforced on every page.
- Requests to the platform are rate limited, and links candidates share (CVs, videos) are checked against Google Web Risk before anyone opens them.
- Code changes are scanned automatically for leaked secrets, and third-party scripts are version-pinned and integrity-checked where the provider allows it.
Your data rights
- Candidates and clients can download their data and delete their account at any time from their account settings.
- Deleted accounts are purged, and residual records are anonymised within 30 days.
- Inactive accounts are removed after 24 months, with an email warning first.
- Marketing email is sent only to people who opted in, and every marketing email has a one-click unsubscribe.
Health information
- Most roles we fill never touch protected health information. Where a role does, the employer is responsible for putting a Business Associate Agreement in place before any access is granted. Access runs through the employer's own systems, and each person gets only the access they need.
Monitoring and incidents
- The platform is monitored around the clock from outside our own infrastructure, and errors are tracked in real time.
- If a personal data breach occurs, we notify affected people and clients within 72 hours of becoming aware of it.
Reporting a security issue
If you believe you've found a security issue, email [email protected] with the subject "Security". Please don't test against live accounts that aren't yours. We'll acknowledge your report within 2 business days.