Security
A factual overview of application safeguards and the operational controls that still require deployment verification.
Draft updated 24 September 2026 · PhilippinesThis content describes the current product and proposed policies. It requires legal and operational review before being treated as a finalized production policy or contract. Operator: JobbhyAI, Philippines. Privacy, security, and service contact: hi@jobbhy.io.
Application controls
- Authenticated workspace access with organization-scoped data queries and role-restricted operations.
- Refresh-session handling and explicit logout; authentication failures clear the stored access token in the client.
- Recorded application history and selected operational audit records.
- Short-lived, hashed Talent Community access-link tokens, with expiry and request throttling.
Deployment responsibilities
Production HTTPS, secret management, database and backup protection, access reviews, monitoring, patching, and recovery procedures must be validated for the deployed environment. Application features alone do not prove that every deployment is configured securely. No guarantee of absolute security is made.
Assurance status
This page does not claim SOC 2, ISO 27001, a completed penetration test, 24/7 monitoring, data residency, or a specific recovery objective. Such statements require current evidence and an approved scope. Ask the listed operator contact for available documentation before procurement.
Reporting a concern
Report security concerns to hi@jobbhy.io using the contact details below. Provide a minimal description and steps to reproduce, without passwords, access tokens, or candidate records. This is a shared privacy, security, and service mailbox, not a guaranteed emergency-response channel. Do not continue testing if it risks accessing another person’s data.
Testing boundaries
This page is not authorization for intrusive testing and does not offer a bug bounty or legal safe harbor. Obtain written authorization before testing. Incidents require assessment and any notifications required by applicable law and agreements; this draft does not promise a universal notification deadline.
Contact Jobbhy.io
For privacy, security, or platform questions, email hi@jobbhy.io. For a hiring decision or an application held by a customer, contact that hiring organization first. Do not send passwords, access tokens, or sensitive documents in your initial message.
Email hi@jobbhy.ioThis opens your email application; nothing is submitted from this page.