Pre-launch legal draft

Security at Jobs.ca

How we protect accounts, resumes, employer workspaces, and the integrity of Canadian job information.

Last updated: July 29, 2026

Secure account access

Jobs.ca uses short-lived, single-use email verification codes and supported identity providers instead of storing a reusable Jobs.ca password. Verification codes are stored only in hashed form and are never written to application logs. Session cookies are HTTP-only, use same-site controls, and are marked secure in production.

Access control

Candidate records are tied to the signed-in user. Employer access comes from an active membership and role, with ownership checks performed when protected information is read or changed. Administrative tools require a separate platform role.

Administrator support views require a recorded reason, expire after 15 minutes, display a persistent support banner, and retain an audit history. Elevated administrator and moderator accounts cannot be opened through this workflow.

Private files and sensitive data

Resumes and verification evidence are private by default. Downloads use short-lived authorization, access is logged, and public pages do not receive database credentials, authentication secrets, or server environment values.

Application and infrastructure safeguards

We validate server requests, apply rate limits to sensitive actions, restrict outbound URLs, keep database access in server-only repositories, and record important trust and membership changes for review.

Production traffic is encrypted in transit. Database, storage, email, and messaging providers are selected and configured with least-privilege access appropriate to their role.

Monitoring and response

We monitor service health, application errors, suspicious activity, imported job quality, and abuse reports. Confirmed incidents are contained, investigated, documented, and communicated when the law requires it.

Report a vulnerability

Use the support form and choose Security report. Include the affected page, a clear reproduction, and the potential impact. Do not access other people's data, disrupt the service, or publish sensitive details before we have had a reasonable opportunity to respond.

Jobs.ca does not currently claim a security certification or public bug-bounty reward. Any future program terms will be published here.