Security
Trust
A plain account of the controls in this build. No certification is claimed.
This page is a product draft for the legal entity named above. Have counsel review it before the service collects payment or personal data in production. Entity: [Legal entity name]. Contact: hello@example.com.
In this build
- Provider secrets are server environment variables. The example file does not contain real keys.
- The health check reports only whether a key is present, not the key itself.
- Responses send X-Content-Type-Options, Referrer-Policy, X-Frame-Options, and a Permissions-Policy.
- Resume uploads are checked for size and type. PDFs are refused until a parser exists.
- The interview room does not upload camera or microphone media.
- Sign-in does not ask for a password, because no authentication service would receive it.
Not in this build
- Accounts, sessions, and authorization.
- Encryption-at-rest claims. There is no application database to encrypt.
- A content security policy. One should be added and tested before launch, not advertised early.
- Independent audits, SOC reports, or ISO certificates.
- A bug-bounty program.
Report a security issue to the contact address on this site. Do not include exploit details in a public form. This page is not a promise that a report will qualify for a reward.