SECURITY BY DESIGN

Security Policy

This Policy describes Jobpassin V2’s security principles, user responsibilities, and the process for reporting a suspected vulnerability or account incident.

Last updated: 25 August 2026
V2 publication notice

This document applies when Jobpassin V2 is made publicly available and will be reviewed against the final production features before launch.

1. Security principles

  • Collect and retain only information reasonably needed for a defined service or legal purpose.
  • Use least-privilege access, role separation, secure defaults, and reviewable administrative actions.
  • Protect data in transit and use appropriate protection for sensitive data at rest.
  • Keep payment-card credentials with the authorised payment processor rather than storing full card data in Jobpassin systems.
  • Test changes, monitor relevant events, patch supported components, and maintain recoverable backups appropriate to the risk.

2. Account protection

Users must choose a unique password, protect authentication factors, sign out from shared devices, and avoid sending passwords or one-time codes by email or chat. Report unknown activity immediately to support@jobpassin.com.

3. Access to candidate information

Access to CVs, assessment materials, identity documents, support conversations, and transaction metadata is limited according to job responsibility and service need. Access may be logged and reviewed. Consultants and service providers receive only the information required for their assigned task.

4. Secure development and operations

Jobpassin’s development process is designed to include code review, dependency review, secret separation, input validation, output encoding, access-control testing, logging, backup verification, and controlled release and rollback procedures proportionate to the change.

5. Payments

Payment entry and authorisation are handled through the selected payment provider’s protected flow. Jobpassin records transaction metadata needed to confirm a service, reconcile payment, prevent fraud, and administer refunds, but does not intend to store the full card number or card security code.

6. Security incidents

Suspected incidents are assessed, contained, investigated, remediated, and documented according to risk. Where law requires notice to users or authorities, Jobpassin will provide it within the applicable period and include available information needed to reduce harm.

7. Reporting a vulnerability

Send a concise report to support@jobpassin.com with the subject “Security Report”. Include the affected URL or feature, reproduction steps, potential impact, and safe evidence. Do not include another user’s personal information unless strictly necessary to explain the issue.

8. Responsible testing boundaries

  • Do not access, change, copy, or delete another person’s data.
  • Do not use social engineering, credential attacks, denial of service, malware, spam, or physical intrusion.
  • Stop testing when sensitive data is exposed and report the issue privately.
  • A report does not create a right to payment or a bug bounty. Any testing must remain lawful and proportionate.

9. Limits and updates

No internet service can promise absolute security. This Policy describes safeguards and intentions, not a guarantee that every threat can be prevented. It will be reviewed as the V2 architecture and risk profile evolve.

END OF DOCUMENTBack to top ↑