Candidates and employers both deserve to know exactly how their data is handled. Here's what we do — and how to report what we missed.
TLS 1.2+ in transit; AES-256 at rest via Supabase (AWS). Passwords are hashed by Supabase Auth — we never see them.
Every table is protected by Postgres RLS policies. Candidates only see their own data; employers only their own pipeline.
Company badges require proving control of an inbox at the company's domain. Scam-scored listings are auto-flagged for review.
Ingested jobs are scored for scam signals; reviews are velocity-limited and burst-flagged; disposable emails are blocked.
We never store card numbers — everything runs through Stripe Checkout with signed webhooks and replay protection.
One-click unsubscribe on every message, SPF/DKIM/DMARC configured, and suppression lists honored across all sends.
Found something? Email security@careersvista.com — details in security.txt.
Related: Privacy policy · Terms · System status