Skip to the page

Security.

How your job search is kept yours, as the site does it today.

Your account is yours.

Every row carries the account it belongs to. Each request runs as a restricted database role that names your account, and a policy on every table (row-level security) refuses any row that is not yours, even if a query forgets to ask for yours. The queries name your account too, so both layers would have to fail before one account saw another account’s rows. Tests try to read, change and delete across accounts, and must fail.

Every private page and request checks your sign-in itself, rather than trusting a check made earlier.

Your agent signs in, and you can take it back.

Your AI agent connects with OAuth 2.1: it sends you to sign in to Jobs.Dog and approve it, so no password or key is pasted anywhere. Its access is checked on every request against the sign-in service’s published keys, and lasts an hour at a time. Press Disconnect on Settings, Connections, and it stops within the hour.

It can add and correct facts. It can also save, pass or star a role through one separate call, which its rules allow only when you ask, and the role shows the name the AI gave itself. It is refused if it tries to set the day you applied, or read or change your settings, email or password.

Jobs.Dog runs no AI and sends nothing you store to any AI company. Your agent’s vendor sees what your agent reads, under that vendor’s terms.

No master key in the app.

The site holds only the public database key a browser is allowed to see, and it opens nothing: the database’s direct web interface is off and every table sits behind row-level security. The service-role key, which would skip those rules, is not in the app.

What your browser may load.

Every page carries a content security policy that allows scripts, styles, fonts and images from this site only:

script-src 'self' 'unsafe-inline'
style-src 'self' 'unsafe-inline'
img-src 'self' data:
font-src 'self'

No other site may frame a page here, and forms post only to this site. Private pages are never kept by a shared cache or shown to search engines.

Passwords and sessions.

Passwords are at least 12 characters, checked against known leaks, and held only as a hash by our sign-in service; the site never stores one. Your sign-in cookie cannot be read by page scripts, travels only over HTTPS, and lasts 30 days from your last visit. Sign out everywhere, on Settings, Account, ends every signed-in session the account has. To stop an agent, press Disconnect on Settings, Connections.

What we keep, and for how long.

  • Everything in your account, for as long as it exists.
  • Delete your account on Settings, Data, with your password and DELETE typed out, and everything on it is deleted at once. A copy can remain in the database’s daily backups for up to 7 days, and then it is gone.
  • Sign-in records, which hold an IP address and a browser name, for 7 days.
  • Error records and our host’s request records, which hold a code, a reference and the page address, never your roles or notes, for about a day.
  • Download everything as one file on Settings, Data, whenever you like.

Whoever runs Jobs.Dog holds the database credentials and could read any row. We look at an account only when its owner asks for help with it, when we need to investigate a security problem or abuse, or when the law requires it.

No system is perfectly secure. If a breach affects your information, we will tell you without unreasonable delay and within the time the law sets, and say what happened and what we are doing about it.

Reporting a problem.

Write to security@jobs.dog with what you found and how to see it. If the site showed you an error, include its code (it starts JD-) and the reference under it. Anything that is not a security problem goes to hello@jobs.dog.