1. Safeguards and limits
JobPassIn uses protected transport, hashed passwords, controlled sessions, input validation and restricted administrative access. Release controls include review, testing and backup/rollback procedures. These measures reduce risk but cannot guarantee absolute security or prevent every incident.
2. Accounts and authorised access
Use a unique password, protect your email account and sign out on shared devices. Do not disclose passwords, one-time codes or card credentials to support. Report unfamiliar activity to support@jobpassin.com. Staff access is controlled by operational responsibilities; authorised support and administrative access is not the same as public access.
3. Card handling
Direct card payment credentials pass through the JobPassIn server to Iyzico transiently. The application does not persist or log full card numbers or security codes; transaction references, statuses and limited card metadata are retained for account and payment administration. Do not include sensitive card data in reports or screenshots.
4. Reporting and testing boundaries
Email support@jobpassin.com with the subject Security Report, the affected URL, concise reproduction steps and safe evidence. Obtain prior written authorisation before testing. Do not access another person's records, run credential attacks, use social engineering, disrupt service, install malware or copy exposed data. Stop and report privately if sensitive data appears.
Sending a report does not authorise testing, establish a legal safe harbour or promise a reward. Share only the minimum evidence needed; do not publish details that expose users while an issue is being assessed.
5. Incidents and updates
We assess suspected incidents and take steps appropriate to the risk. Notice to affected people or authorities is provided where required by the applicable law and its deadlines. Not every report is a confirmed breach, and we do not promise a fixed response or resolution time in this policy. Material changes to these practices are reflected here.
