Security & Data Handling

Every CV that passes through this platform contains someone's real personal details -- name, contact information, full work history. Here's exactly how that data is protected, in plain terms.

Last updated: August 2026

No Public Sign-Up

Every account is created by us directly for a known client. There is no public registration form, so there's no way for an unknown party to create an account on the platform.

Strict Data Isolation

Each client's candidate CVs are kept completely separate from every other client's. One client can never see or download another client's data.

Encrypted in Transit

All traffic to and from the platform runs over HTTPS. Your files and login details are never sent over an unencrypted connection.

Passwords Are Hashed

Passwords are never stored as plain text. They're secured using industry-standard password hashing, so even we can't see your actual password.

Brute-Force Protection

Login attempts are rate-limited, so automated password-guessing attacks are blocked long before they could get anywhere.

Automatic Data Retention

Processed CVs aren't kept indefinitely. They're automatically deleted after 7 days rather than sitting on our servers forever.

No Internal Details Exposed

If something goes wrong, error messages never reveal internal technical details that could help someone probe the system for weaknesses.

Where we're still growing

We don't hold formal certifications like ISO 27001 yet -- that's a significant undertaking we plan to pursue once it's justified by the scale we're operating at, and we'd rather tell you that plainly than imply otherwise. What's listed above isn't marketing language -- it's what's actually built and running today.

Have a specific security question, or need details for your own vendor review process? Reach out via the contact form and we'll answer directly.

See also our Privacy Policy for what data we collect and your rights over it.