Security
How your information is protected, in specific terms.
Encryption
- Everything in transit is encrypted with TLS.
- Identity data and original resume files are encrypted at rest under a dedicated key used for nothing else.
- Searchable profile data is stored separately, under separate encryption, and holds nothing that identifies you.
Access
- The systems that serve recruiter search have no permission to read identity data. This is enforced by access policy, not by application code that could be changed by mistake.
- The service that stores your identity details cannot read them back. Only your own signed-in session, and the consent flow you approve, can.
- Passwords are handled by a managed identity provider and are never stored by us in any recoverable form.
- Sessions end after thirty idle minutes, with a warning two minutes before, so a browser left open on a shared machine does not stay signed in as you.
AI processing
Profile summaries, role extraction, interview preparation and the content checks on the feed all run on models hosted inside our own cloud account. Your resume is never sent to a third-party AI provider, and is never used to train a publicly available model.
Abuse and rate limits
Requests are limited per IP address before sign-in and per account after it, and the expensive operations — summaries, uploads, document extraction — carry their own lower ceilings. This is why an unusual burst of activity may be refused; it is also what stops one account from mining the platform.
Reporting a vulnerability
If you believe you have found a security issue, email security@incognitoh.com with enough detail to reproduce it. Please give us a reasonable opportunity to fix it before disclosing it publicly. We will not pursue action against researchers acting in good faith.