Trust center
Security overview
Beta notice · Updated August 8, 2026
Controls implemented
Supabase Row Level Security protects candidate-owned records. Résumé storage is private and constrained to an authenticated user folder. Browser code uses only a publishable key; secret service credentials are prohibited.
Consent boundary
Recruiter conversations require a verified recruiter and an active, non-withdrawn candidate consent record. Participants alone can read conversations and messages.
Responsible disclosure
Do not include résumés, credentials, or personal information in a vulnerability report. A monitored disclosure address, response SLA, penetration test, incident process, and public security.txt remain launch dependencies.
No certification claim
PavedIT does not currently claim SOC 2, ISO 27001, HIPAA, or other third-party certification.