Information Security Policy
Last updated: January 5, 2026
Encrypted Data
All data encrypted in transit and at rest
OAuth Security
Secure Google OAuth 2.0 integration
Secure Infrastructure
Enterprise-grade cloud hosting
1. Security Overview
RECRUITED is committed to maintaining the highest standards of information security to protect our users' data, including sensitive recruiting communications and Gmail integration data. This policy outlines our security practices, controls, and commitments.
We adhere to industry best practices and comply with Google API Limited Use Requirements, ensuring that your Gmail data is handled with the utmost care and protection.
2. Access Control
2.1 User Authentication
- Secure password requirements with minimum complexity standards
- Google OAuth 2.0 for Gmail integration with minimal scope requests
- Session management with automatic timeout and secure token handling
- Account lockout after multiple failed authentication attempts
2.2 Authorization
- Role-based access control (RBAC) for all system functions
- Principle of least privilege applied to all access grants
- Regular access reviews and prompt revocation for departed users
- Supporter access controls with granular permission levels
3. Data Protection
3.1 Encryption
- In Transit: All data transmitted using TLS 1.2 or higher (HTTPS)
- At Rest: Database encryption using AES-256
- OAuth Tokens: Encrypted storage with secure key management
3.2 Data Handling
- Data minimization: We only collect and retain data necessary for the service
- Data segregation: User data is logically separated
- Secure deletion: Data is securely erased upon account deletion request
- Backup encryption: All backups are encrypted and access-controlled
4. Infrastructure Security
- Hosted on enterprise-grade cloud infrastructure with SOC 2 Type II compliance
- Network security with firewalls and intrusion detection
- Regular security patching and vulnerability management
- Geographic redundancy and disaster recovery capabilities
- DDoS protection and rate limiting
5. Gmail API Security
RECRUITED's Gmail integration follows Google's security requirements and Limited Use policy:
- Minimal Scopes: We request only the Gmail scopes necessary for sending emails on your behalf
- Token Security: OAuth refresh tokens are encrypted and stored securely
- No Data Sharing: Your Gmail data is never shared with third parties
- Revocable Access: You can revoke Gmail access at any time from your Google Account settings
- Audit Logging: All Gmail API operations are logged for security monitoring
6. Application Security
6.1 Secure Development
- Secure coding practices following OWASP guidelines
- Code review for all changes before deployment
- Dependency vulnerability scanning
- Static application security testing (SAST)
6.2 Security Testing
- Regular vulnerability assessments
- Penetration testing by qualified security professionals
- Bug bounty program for responsible disclosure
7. Monitoring and Logging
- Comprehensive activity logging for security events
- Real-time monitoring and alerting for suspicious activity
- Log retention for security analysis and compliance
- Regular log review and anomaly detection
8. Employee Security
- Background checks for personnel with data access
- Security awareness training
- Confidentiality agreements
- Access revocation procedures for departing personnel
9. Third-Party Security
- Vendor security assessments before engagement
- Data processing agreements with all sub-processors
- Regular review of third-party security practices
- Limited data sharing with third parties (see Privacy Policy)
10. Compliance
- Google API Limited Use: Full compliance with Google's Limited Use Requirements
- Age Requirements: Service restricted to users 13 years and older (COPPA compliance)
- Data Protection: Adherence to applicable data protection regulations
- CASA Assessment: Completed Cloud Application Security Assessment for Google OAuth
11. Incident Response
We maintain a comprehensive incident response program. For details, see our Incident Response Policy.
12. Vulnerability Disclosure
We welcome responsible security research. For details on how to report vulnerabilities, see our Vulnerability Disclosure Policy.
13. Contact Information
For security inquiries or to report a security concern:
- Security Team: security@recruitedcrm.com
- General Support: contact@recruitedcrm.com