SECURITY
How we protect your data.
A short, honest overview of the security controls in place. If you need details for a compliance review, contact us and we will share more under NDA where appropriate.
Effective 16 August 2026 · Applies to jobdownup.app and the jobdownup service
DRAFT — LEGAL REVIEW PENDING
Substantive template — not a substitute for advice from a qualified lawyer. Every placeholder in [[BRACKETS]] below must be filled with real information before ads run.
1. Principles
- Least privilege by default. No one has more access than they need for their role.
- Encrypt everywhere. In transit and at rest.
- Deletion is real. When you delete an account, we delete the data — not soft-delete, not archive-forever.
- No CV in logs. Application logs redact profile content.
2. Encryption
- All traffic to the site is TLS 1.2+ with HSTS.
- Databases and object storage are encrypted at rest by our hosting provider (AES-256).
- Secrets are stored in the provider’s encrypted secrets store and never committed to source control.
3. Access control
- MFA is required on all admin accounts (hosting, payments, email, code).
- Production data access is limited to the operator and logged.
- Code review is required before deployment to production.
4. Hosting & network
- Hosted on Vercel (see Subprocessors). SOC 2 Type II reports available from Vercel on request.
- DDoS protection and a Web Application Firewall are provided at the edge by Vercel.
- EU region is used where available for data at rest.
5. Application security
- Dependency updates are applied on a regular cadence; critical CVEs are patched within one working day of disclosure.
- Automated builds fail on known-vulnerable dependencies.
- Content Security Policy and other HTTP security headers are enabled.
- Rate limiting and bot detection protect authentication endpoints (Vercel BotID + platform WAF rules).
6. Backups & durability
- The database is managed Postgres (Neon). Durability and point-in-time recovery come from the provider’s continuously retained write-ahead log; we do not operate a separate backup system of our own.
- Data is encrypted in transit and at rest.
- The point-in-time recovery window is currently 7 days. Data older than that is not separately recoverable, so we treat deletion as final — see retention.
- Restores are verified by actually performing one: we recover the database to an earlier point in time on an isolated copy and check the data is present and usable. Last performed 2026-08-25, passed. We state the date of the last test rather than a schedule, because a schedule nobody runs reads exactly like one that works.
7. Monitoring & incident response
- Application errors and platform metrics are monitored.
- In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours (GDPR Art. 33) and affected users where required (Art. 34).
- Post-mortems for material incidents are written and, where they teach something useful, shared publicly.
8. Reporting a vulnerability
If you have discovered a security issue, please report it privately to security@jobdownup.app. Do not post it publicly before we have had a chance to fix it. We aim to acknowledge within 2 working days and to remediate critical issues within 14 days. We do not currently offer a paid bug bounty, but we credit reporters (with permission) in release notes.