Legal
Security
How we protect accounts, data, and employer verification on JobLyne.
Last updated: August 25, 2026
Security at JobLyne
Hiring platforms handle sensitive personal and business data. We design JobLyne with layered controls so candidates, recruiters, and companies can collaborate without exposing more information than each workflow requires.
Account protection
- Email OTP verification for sign-up and sensitive account changes.
- Optional OAuth sign-in (Google, LinkedIn) with secure token handling.
- HttpOnly session cookies and refresh-token rotation for authenticated sessions.
- Role-based access across candidate, recruiter, company, and admin portals.
Data protection
- TLS encryption for data in transit across all production endpoints.
- Segregated media access rules for résumés and verification documents.
- Candidate contact details gated behind application or unlock workflows for employers.
- Admin-reviewed company verification before full employer capabilities are enabled.
Employer verification
Companies and recruiter agencies undergo admin review before posting jobs or browsing candidates. Domain verification (DNS TXT, meta tag, or file proof) adds an additional trust tier for public profiles and publishing rights.
Responsible disclosure
If you discover a security vulnerability, please report it to support@joblyne.com. Include steps to reproduce, impact assessment, and your contact details. We aim to acknowledge reports within two business days.
Please do not publicly disclose issues until we have had a reasonable opportunity to investigate and remediate.
Your responsibilities
- Use a strong, unique password and enable available security options.
- Do not share login credentials across team members — use proper team invites for company accounts.
- Report suspicious messages, phishing attempts, or unauthorized profile changes immediately.