Security
Candidate profiles and hiring records are sensitive. This page describes the protections we have in place today. We do not claim certifications we do not hold.
Accounts and sessions
- Passwords are stored as salted hashes, never in plain text.
- Sign-in uses a first-party cookie that scripts cannot read (HttpOnly), is sent only over HTTPS on the live site, and expires after one day.
- Sessions can be revoked server-side, for example after a password change.
- Sign-in attempts and other sensitive endpoints are rate limited.
Data in transit and at rest
- The site is served over HTTPS with HSTS.
- Uploaded files such as résumés are scanned for malware before they are stored, and are kept in private storage. They are served through authenticated requests, not public links.
- Connected account tokens, such as calendar sign-ins, are stored encrypted.
Access control
- Employer data is separated by organisation: team members work with their own organisation's jobs and applications, and see only what their role allows.
- Candidates have visibility settings that control who can find their profile. Expected pay is never shown publicly.
Payments
Payments are handled by Razorpay. Card and bank details are entered with Razorpay, and payment confirmations are verified before a plan is activated.
Report a vulnerability
If you believe you have found a security problem, email support@nicefound.com with the details and steps to reproduce. Please give us reasonable time to fix it before sharing it publicly, and do not access other people's data or disrupt the service while testing.