← Back to PavedIT

Trust center

Security overview

Beta notice · Updated August 8, 2026

Controls implemented

Supabase Row Level Security protects candidate-owned records. Résumé storage is private and constrained to an authenticated user folder. Browser code uses only a publishable key; secret service credentials are prohibited.

Consent boundary

Recruiter conversations require a verified recruiter and an active, non-withdrawn candidate consent record. Participants alone can read conversations and messages.

Responsible disclosure

Do not include résumés, credentials, or personal information in a vulnerability report. A monitored disclosure address, response SLA, penetration test, incident process, and public security.txt remain launch dependencies.

No certification claim

PavedIT does not currently claim SOC 2, ISO 27001, HIPAA, or other third-party certification.