Security

Last updated: 2 August 2026

Draft. Items marked [[ LIKE THIS ]] are filled in once the company is registered.

JobAgent holds your CV, your job pipeline and, if you connect them, tokens for your own AI and data accounts. This page describes how that is protected — and, at the end, what is not in place yet, because a security page that only lists strengths is not much use to you.

Keeping accounts apart

This is the property everything else rests on. The database is shared, so isolation is enforced in code rather than by separate instances:

Authentication

Encryption

Where it runs

Outbound requests

The Service follows links that come from job postings — untrusted input. A guard resolves every such URL first and refuses private, loopback, link-local and cloud-metadata addresses, re-checking after each redirect, so a crafted posting cannot make our servers reach something internal.

Abuse and cost controls

Logging and auditing

Your own controls

What is not in place yet

Stated plainly so you can judge the risk yourself:

Reporting a vulnerability

If you find a security problem, please report it privately to [[ SECURITY EMAIL ON YOUR OWN DOMAIN, e.g. security@… ]] before disclosing it publicly. Tell us what you found and how to reproduce it; we will confirm receipt, keep you updated, and credit you if you would like. Please do not access, modify or retain other people's data while testing.

See also our Privacy Policy and Terms of Service.
[[ YOUR REGISTERED NAME ]] · sole trader (ditta individuale) established in Italy · VAT number (partita IVA) [[ NUMBER ]]