jobdownup
SECURITY

How we protect your data.

A short, honest overview of the security controls in place. If you need details for a compliance review, contact us and we will share more under NDA where appropriate.

Effective 16 August 2026 · Applies to jobdownup.app and the jobdownup service
DRAFT — LEGAL REVIEW PENDING
Substantive template — not a substitute for advice from a qualified lawyer. Every placeholder in [[BRACKETS]] below must be filled with real information before ads run.

1. Principles

  • Least privilege by default. No one has more access than they need for their role.
  • Encrypt everywhere. In transit and at rest.
  • Deletion is real. When you delete an account, we delete the data — not soft-delete, not archive-forever.
  • No CV in logs. Application logs redact profile content.

2. Encryption

  • All traffic to the site is TLS 1.2+ with HSTS.
  • Databases and object storage are encrypted at rest by our hosting provider (AES-256).
  • Secrets are stored in the provider’s encrypted secrets store and never committed to source control.

3. Access control

  • MFA is required on all admin accounts (hosting, payments, email, code).
  • Production data access is limited to the operator and logged.
  • Code review is required before deployment to production.

4. Hosting & network

  • Hosted on Vercel (see Subprocessors). SOC 2 Type II reports available from Vercel on request.
  • DDoS protection and a Web Application Firewall are provided at the edge by Vercel.
  • EU region is used where available for data at rest.

5. Application security

  • Dependency updates are applied on a regular cadence; critical CVEs are patched within one working day of disclosure.
  • Automated builds fail on known-vulnerable dependencies.
  • Content Security Policy and other HTTP security headers are enabled.
  • Rate limiting and bot detection protect authentication endpoints (Vercel BotID + platform WAF rules).

6. Backups & durability

  • The database is managed Postgres (Neon). Durability and point-in-time recovery come from the provider’s continuously retained write-ahead log; we do not operate a separate backup system of our own.
  • Data is encrypted in transit and at rest.
  • The point-in-time recovery window is currently 7 days. Data older than that is not separately recoverable, so we treat deletion as final — see retention.
  • Restores are verified by actually performing one: we recover the database to an earlier point in time on an isolated copy and check the data is present and usable. Last performed 2026-08-25, passed. We state the date of the last test rather than a schedule, because a schedule nobody runs reads exactly like one that works.

7. Monitoring & incident response

  • Application errors and platform metrics are monitored.
  • In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours (GDPR Art. 33) and affected users where required (Art. 34).
  • Post-mortems for material incidents are written and, where they teach something useful, shared publicly.

8. Reporting a vulnerability

If you have discovered a security issue, please report it privately to security@jobdownup.app. Do not post it publicly before we have had a chance to fix it. We aim to acknowledge within 2 working days and to remediate critical issues within 14 days. We do not currently offer a paid bug bounty, but we credit reporters (with permission) in release notes.