Information Security Policy

    Last updated: January 5, 2026

    Encrypted Data

    All data encrypted in transit and at rest

    OAuth Security

    Secure Google OAuth 2.0 integration

    Secure Infrastructure

    Enterprise-grade cloud hosting

    1. Security Overview

    RECRUITED is committed to maintaining the highest standards of information security to protect our users' data, including sensitive recruiting communications and Gmail integration data. This policy outlines our security practices, controls, and commitments.

    We adhere to industry best practices and comply with Google API Limited Use Requirements, ensuring that your Gmail data is handled with the utmost care and protection.

    2. Access Control

    2.1 User Authentication

    • Secure password requirements with minimum complexity standards
    • Google OAuth 2.0 for Gmail integration with minimal scope requests
    • Session management with automatic timeout and secure token handling
    • Account lockout after multiple failed authentication attempts

    2.2 Authorization

    • Role-based access control (RBAC) for all system functions
    • Principle of least privilege applied to all access grants
    • Regular access reviews and prompt revocation for departed users
    • Supporter access controls with granular permission levels

    3. Data Protection

    3.1 Encryption

    • In Transit: All data transmitted using TLS 1.2 or higher (HTTPS)
    • At Rest: Database encryption using AES-256
    • OAuth Tokens: Encrypted storage with secure key management

    3.2 Data Handling

    • Data minimization: We only collect and retain data necessary for the service
    • Data segregation: User data is logically separated
    • Secure deletion: Data is securely erased upon account deletion request
    • Backup encryption: All backups are encrypted and access-controlled

    4. Infrastructure Security

    • Hosted on enterprise-grade cloud infrastructure with SOC 2 Type II compliance
    • Network security with firewalls and intrusion detection
    • Regular security patching and vulnerability management
    • Geographic redundancy and disaster recovery capabilities
    • DDoS protection and rate limiting

    5. Gmail API Security

    RECRUITED's Gmail integration follows Google's security requirements and Limited Use policy:

    • Minimal Scopes: We request only the Gmail scopes necessary for sending emails on your behalf
    • Token Security: OAuth refresh tokens are encrypted and stored securely
    • No Data Sharing: Your Gmail data is never shared with third parties
    • Revocable Access: You can revoke Gmail access at any time from your Google Account settings
    • Audit Logging: All Gmail API operations are logged for security monitoring

    6. Application Security

    6.1 Secure Development

    • Secure coding practices following OWASP guidelines
    • Code review for all changes before deployment
    • Dependency vulnerability scanning
    • Static application security testing (SAST)

    6.2 Security Testing

    • Regular vulnerability assessments
    • Penetration testing by qualified security professionals
    • Bug bounty program for responsible disclosure

    7. Monitoring and Logging

    • Comprehensive activity logging for security events
    • Real-time monitoring and alerting for suspicious activity
    • Log retention for security analysis and compliance
    • Regular log review and anomaly detection

    8. Employee Security

    • Background checks for personnel with data access
    • Security awareness training
    • Confidentiality agreements
    • Access revocation procedures for departing personnel

    9. Third-Party Security

    • Vendor security assessments before engagement
    • Data processing agreements with all sub-processors
    • Regular review of third-party security practices
    • Limited data sharing with third parties (see Privacy Policy)

    10. Compliance

    • Google API Limited Use: Full compliance with Google's Limited Use Requirements
    • Age Requirements: Service restricted to users 13 years and older (COPPA compliance)
    • Data Protection: Adherence to applicable data protection regulations
    • CASA Assessment: Completed Cloud Application Security Assessment for Google OAuth

    11. Incident Response

    We maintain a comprehensive incident response program. For details, see our Incident Response Policy.

    12. Vulnerability Disclosure

    We welcome responsible security research. For details on how to report vulnerabilities, see our Vulnerability Disclosure Policy.

    13. Contact Information

    For security inquiries or to report a security concern: