Back to IR35Careers

Trust centre

Security and Responsible Disclosure

How IR35Careers protects contractor information and how to report a security concern without putting other users at risk.

Last updated 20 August 2026

Security controls

  • Supabase authentication and owner-scoped row-level security protect account records.
  • CV storage is private and separated by user identifier.
  • Server-only credentials are excluded from browser bundles.
  • Inbound webhooks require feature flags, signatures and idempotency identifiers.
  • Live submission, email and billing providers default to off until their safety gates pass.

Report a vulnerability

Use Contact and begin the message with “Security disclosure”. Include the affected URL, impact, safe reproduction steps and a contact address. Do not include credentials, other users' personal information or active exploit payloads.

There is not currently a paid bug-bounty programme. Good-faith reports are still welcomed and will be triaged responsibly.

Safe testing rules

Do not access another person's account or data, cause service degradation, send spam, upload malware, perform denial-of-service testing, use social engineering, test third-party providers, or retain information encountered accidentally. Stop immediately if you encounter personal information.

What happens next

We will acknowledge a reproducible report, assess severity, preserve relevant evidence and coordinate a proportionate fix. Public disclosure should wait until a fix is available and users are no longer exposed.