RecruitModo

Security

Security

This page summarizes the current security posture and responsible disclosure path for RecruitModo.

Last updated: June 19, 2026

Security Model

RecruitModo uses Supabase Auth, server-side authorization checks, organization-scoped data access, role permissions, and audit events to support a tenant-aware enrollment intelligence workflow.

The product is designed so AI research jobs can generate recommendations, but humans approve review queues, content, campaign launches, partnerships, and other sensitive actions.

Application Protections

The public application is served over HTTPS with HSTS, baseline browser security headers, route protection for app screens, and service-role access restricted to server-side code.

Security-sensitive product actions should be logged through audit events and checked against the signed-in user's organization permissions.

Responsible Disclosure

If you believe you found a vulnerability, contact demo@recruitmodo.com with a clear description, affected URL, reproduction steps, and any non-sensitive evidence.

Do not access, modify, delete, exfiltrate, or disrupt data that does not belong to you. Do not run destructive tests or high-volume scans against RecruitModo without written authorization.

Production Readiness

Before use with live student, prospect, applicant, or institutional data, RecruitModo should complete a security review covering data retention, incident response, SSO configuration, logging, backup expectations, vendor agreements, and AI provider data handling.