Security

How Sidedoor protects your resume, your credentials and your sending — and how to report a vulnerability.

LAST UPDATED 12 SEPTEMBER 2026

Infrastructure

  • TLS 1.2+ on everything in transit, AES-256 at rest for databases and uploaded files.
  • Hosting on providers with SOC 2 Type II compliance, in access-controlled regions.
  • Isolated environments: production data never leaves production, and never appears in development or test.
  • Daily encrypted backups with restores exercised on a schedule.

Access

  • Least privilege, granted per role and reviewed quarterly.
  • Mandatory two-factor authentication for every internal system.
  • Passwords stored hashed with a modern memory-hard algorithm — we cannot read yours.
  • Every production access is logged and the logs are retained.

Application

  • Dependencies scanned continuously; security patches applied on a defined clock.
  • Code review required on every change that touches auth, billing or user data.
  • Rate limits and abuse detection on sending, so a compromised account cannot be turned into a spam cannon.

Your part

Use a unique password, keep your email account secure, and tell us straight away if you think someone else is in your account.

Reporting a vulnerability

Email support@usesidedoor.com with the details and, if you can, a proof of concept. We acknowledge within 2 business days and keep you updated until it is fixed. Test only against your own account, do not access or alter anyone else's data, and do not run denial-of-service or social engineering. Researchers who follow that will not face legal action from us.