Security
Last updated · 2026-06-18 · placeholder
Client-side delivery
Job applications are submitted from your own browser, in your own session, on your own IP. We never operate a job board on your behalf from a remote server, and we never ask for your job-board passwords.
Account
- Passwords are hashed (bcrypt-class) and never logged.
- JWT sessions are scoped per device and revocable from settings.
- 2FA is on our roadmap for the first public release.
Reporting an issue
Please open a ticket at security@vantage or follow the SECURITY.md process in our repo. We take any account-safety report seriously.