Security at
Pharmagen Recruit

We handle candidate and client information with care. This page summarises how the platform protects it. For anything not covered here, contact [email protected].

Last updated 2026-09-27

Where your data lives

  • The platform's database is hosted by Supabase in Australia (Sydney region). Transfers are protected by the Standard Contractual Clauses in Supabase's Data Processing Agreement.
  • The website is served through Cloudflare's global network.
  • Email is sent through Resend. Error reports go to Sentry (EU region).
  • The full list of service providers is in our Privacy Policy.

Encryption

  • All traffic to the website and platform uses HTTPS (TLS), with HSTS enforced.
  • Data is encrypted at rest by our database provider.
  • Direct database connections require encryption and are limited to named administrator machines.

Accounts and access

  • Passwords are checked against known data breaches and stored only as secure hashes.
  • Two-factor authentication (authenticator app) is available to every account.
  • Sign-up, login and password reset are protected by a bot check.
  • Sessions expire after inactivity, and changing an email address or password requires confirming the current password.
  • Every table in the database has row-level security: each person can only reach their own records, and staff access is checked on the server for every request.
  • Actions by our staff and administrators are recorded in an audit log.

Application security

  • A strict Content Security Policy, clickjacking protection and other security headers are enforced on every page.
  • Requests to the platform are rate limited, and links candidates share (CVs, videos) are checked against Google Web Risk before anyone opens them.
  • Code changes are scanned automatically for leaked secrets, and third-party scripts are version-pinned and integrity-checked where the provider allows it.

Your data rights

  • Candidates and clients can download their data and delete their account at any time from their account settings.
  • Deleted accounts are purged, and residual records are anonymised within 30 days.
  • Inactive accounts are removed after 24 months, with an email warning first.
  • Marketing email is sent only to people who opted in, and every marketing email has a one-click unsubscribe.

Health information

  • Most roles we fill never touch protected health information. Where a role does, the employer is responsible for putting a Business Associate Agreement in place before any access is granted. Access runs through the employer's own systems, and each person gets only the access they need.

Monitoring and incidents

  • The platform is monitored around the clock from outside our own infrastructure, and errors are tracked in real time.
  • If a personal data breach occurs, we notify affected people and clients within 72 hours of becoming aware of it.

Reporting a security issue

If you believe you've found a security issue, email [email protected] with the subject "Security". Please don't test against live accounts that aren't yours. We'll acknowledge your report within 2 business days.