Security isn't a feature - it's the foundation. Every control listed on this page is one that is actually in the product, not one we hope to add.
Passwords
Bcrypt hashed
Card Details
Never stored
Stripe-hosted checkout
Passwords are hashed with bcrypt. We never store or email a readable password.
Payments run through Stripe-hosted checkout, so card details never reach our servers.
Every API route verifies your signed token and your role before it returns data.
Resumes are served over signed links that stop working an hour after they are issued.
Recruit Myself is a small operation, so instead of describing a security desk we don't staff, here is what is actually enforced on every request. Standard hardened HTTP headers, request sanitising against injection, and a browser origin allowlist sit in front of all of it.
Bcrypt
Password Hashing
Token + Role
Checked Per Request
Rate Limited
Sign-In and Reset
Signed Links
Resume Downloads
No legalese dungeons. Click any section to read the full detail.
Something unclear, or think you have found a vulnerability? Write to us and we will read it. Tell us what you saw and how to reproduce it.