Trust center

Security claims should be specific.

This page describes safeguards present in the product today, practical limits, and the safest way to report a concern.

Last reviewed July 11, 2026

Credentials
Bcrypt hashing

Plain-text passwords are not stored.

Sessions
Short-lived + rotated

Access sessions expire; refresh sessions rotate.

Data access
Account scoped

Private records are tied to an authenticated user.

Safeguards in the current product

  • Passwords are hashed with bcrypt before storage.
  • Protected APIs require an authenticated access token.
  • Access tokens are short-lived, and refresh tokens rotate when renewed.
  • Server-side refresh-token records contain a one-way token hash rather than the token itself.
  • Candidate profiles, documents, applications, and related records are associated with a user account.
  • Production traffic is served over HTTPS by the hosting platform.

What you can do

Use a unique password, keep the device and browser you use to sign in protected, and sign out on shared machines. Do not paste passwords, access tokens, government identifiers, banking information, or unrelated sensitive records into profile or AI-writing fields.

Generated documents may contain personal details you supplied. Review them before sharing and remove information that a prospective employer does not need.

AI and service-provider boundary

Some requested features send the minimum relevant prompt context to a configured AI provider to produce a result. Hosting and infrastructure providers also process data needed to run the service. Their systems are outside ApplyDjin’s direct code boundary.

See Privacy for the categories of information involved and Cookies & storage for browser-side storage.

Assurance and current limits

ApplyDjin does not currently claim SOC 2, ISO 27001, PCI DSS, HIPAA, or another independent security certification. The safeguards above are implementation facts, not a guarantee that incidents are impossible.

Security practices and this page will evolve with the product. Material claims should appear here only after the corresponding control exists.

Report a security concern

Use the guidance on Contact & support and mark the message as a security report. Describe the affected page and what happened, but do not send passwords, live session tokens, or another person’s private data.

Please report suspected account exposure promptly and stop using the affected session until it has been reviewed.