Back to home
VANTAGE

Security

Last updated · 2026-06-18 · placeholder

Client-side delivery

Job applications are submitted from your own browser, in your own session, on your own IP. We never operate a job board on your behalf from a remote server, and we never ask for your job-board passwords.

Account

  • Passwords are hashed (bcrypt-class) and never logged.
  • JWT sessions are scoped per device and revocable from settings.
  • 2FA is on our roadmap for the first public release.

Reporting an issue

Please open a ticket at security@vantage or follow the SECURITY.md process in our repo. We take any account-safety report seriously.