Security
Security
This page summarizes the current security posture and responsible disclosure path for RecruitModo.
Last updated: June 19, 2026
Security Model
RecruitModo uses Supabase Auth, server-side authorization checks, organization-scoped data access, role permissions, and audit events to support a tenant-aware enrollment intelligence workflow.
The product is designed so AI research jobs can generate recommendations, but humans approve review queues, content, campaign launches, partnerships, and other sensitive actions.
Application Protections
The public application is served over HTTPS with HSTS, baseline browser security headers, route protection for app screens, and service-role access restricted to server-side code.
Security-sensitive product actions should be logged through audit events and checked against the signed-in user's organization permissions.
Responsible Disclosure
If you believe you found a vulnerability, contact demo@recruitmodo.com with a clear description, affected URL, reproduction steps, and any non-sensitive evidence.
Do not access, modify, delete, exfiltrate, or disrupt data that does not belong to you. Do not run destructive tests or high-volume scans against RecruitModo without written authorization.
Production Readiness
Before use with live student, prospect, applicant, or institutional data, RecruitModo should complete a security review covering data retention, incident response, SSO configuration, logging, backup expectations, vendor agreements, and AI provider data handling.