TrueCallingTrueCalling
Security

Built to be trusted with your career.

You hand us the most personal record you have — your professional history. Protecting it is not a feature. It's the foundation.

How we protect your data.

Encrypted end to end

Your data is encrypted in transit (TLS) and at rest. It is protected on the way to us and while it sits with us.

Least-privilege access

Access to production data is tightly scoped, logged, and granted only where genuinely needed — never by default.

Data minimization

We collect only what we need to navigate on your behalf. Less data held is less data at risk.

Never sold

Your profile powers your matches and nothing else. We do not sell your personal information, ever.

Hardened infrastructure

We build on reputable cloud infrastructure with network isolation, managed secrets, and regular patching.

Continuous monitoring

We monitor for anomalies and maintain a plan to detect, respond to, and learn from incidents.

Our practices

The specifics, plainly stated.

Security is a practice, not a badge. Here's what that looks like day to day.

Data protection

TLS encryption for all data in transit
Encryption at rest for stored profiles and documents
Backups with defined retention and recovery testing

Access & accounts

Least-privilege, audited access to production systems
Secure authentication and session handling
Prompt off-boarding of access when roles change

Infrastructure

Reputable cloud hosting with network isolation
Managed secrets — no credentials in source code
Regular dependency and platform patching

Privacy by design

Data minimization built into what we collect
Self-serve export and deletion for every user
No sale of personal data and no third-party model training

You stay in control of your data.

Export your jobs and matches, or delete individual data or your entire account, any time — from your data settings. What you share powers your matches and nothing else. We never sell it.

Responsible disclosure

Found something? Tell us.

We welcome reports from security researchers. If you believe you've found a vulnerability, email us with the details and steps to reproduce. We'll acknowledge your report, keep you updated, and won't pursue action against good-faith research.

Please give us reasonable time to remediate before any public disclosure.

Report a vulnerability
[email protected]
Acknowledgementwithin 3 business days
Encrypted reportsPGP on request
Safe harborgood-faith research