getremotejobs
Trust & security

We take your data seriously.

Security isn't a certification you slap on a marketing page — it's the set of decisions that went into every layer of the product. Here's what we actually do.

Encryption

TLS 1.2 or better for every request. Database storage encrypted at rest with AES-256. Backup volumes encrypted in the same key hierarchy.

Access controls

Row-level security enforced in Postgres — not just at the application layer. Least-privilege IAM for employees. MFA required for admin access.

Isolation

Multi-tenant data model scoped by org_id at every query. Recruiter workspaces cannot see each other. Candidate PII never leaves the candidate's control without explicit opt-in.

Incident response

24-hour on-call rotation with documented playbooks. Breach notification within 72 hours per GDPR Article 33. Post-mortems published to customers.

Compliance posture

Where we are on the compliance journey.

GDPR / UK GDPR
Operational

Data subject request tooling built in. Subprocessors under contract. DPA available for customers processing EU/UK data.

CCPA / CPRA
Operational

California residents can access, correct, delete, and opt out directly from the product. No sale of personal information.

SOC 2 Type II
In progress

Controls implemented. Audit observation period begins this year. Full report will be available under NDA once complete.

ISO 27001
Planned

On the 18-month roadmap. Happy to discuss timeline and scope with enterprise customers.

PCI DSS
Scoped out

Card data is handled by Stripe; getremotejobs never stores raw payment details.

HIPAA
Not applicable

Job and career data is not PHI. We do not process health information as part of the Service.

Subprocessors

Who touches your data, and why.

ProviderPurposeData categoryLocation
SupabaseDatabase, auth, object storageAll customer + candidate dataUS (AWS us-east-1)
VercelApplication hostingRequest metadata, no content at restGlobal edge
AnthropicResume parsing (Claude Haiku)Resume content (ephemeral)US
OpenAIEmbedding generationResume + job text (ephemeral)US
ResendTransactional + alert emailEmail address, message contentUS
StripePayment processingBilling metadata (no card data)US / EU
SentryError monitoringStack traces, request metadataUS

Changes to this list are announced 30 days in advance to enterprise customers. For the full DPA, including Standard Contractual Clauses for EU transfers, see /dpa.

Responsible disclosure

Found something? Tell us.

If you've discovered a security issue, we want to hear about it. We don't sue security researchers acting in good faith. Our disclosure policy and PGP contact live at /.well-known/security.txt. Bounties are paid on a case-by-case basis for impactful, previously-unreported findings.

[email protected]