Security & privacy

Every file checked.
Each side private.

Hiring means sharing personal details and opening files from people you don't know yet. Here's how HireDec. keeps both safe, in plain words.

Between the two sides

One application. Two private sides.

Candidates and hiring teams work on the same application. What each side keeps for itself never crosses over.

Only the candidate sees

  • Their private notes and to-dos
  • Their interview preparation notes
  • The labels they give their CVs
  • The names of their profiles
  • Their applications to other companies

Both sides see

  • The job's stages, and where the application is
  • The profile and CV that were sent, as they were then
  • Interview times, assignments and their files
  • Messages, offers and decisions

Only the hiring team sees

  • The team's internal notes about a candidate
  • Its other candidates
  • Its team, roles and invitations

Every uploaded file

Checked before it's stored. Served so it can't run.

CVs, assignment briefs, hand-ins, photos and logos all go through the same steps. We rely on established open-source tools instead of writing our own detection.

  1. 01

    What it really is

    The type comes from the file's content, never its name. Content that doesn't match its name is refused, as is any kind we don't take.

    file-type
  2. 02

    Scanned for malware

    Every upload is scanned before it's stored. If the scanner can't be reached, the upload is refused rather than let through.

    ClamAV
  3. 03

    Documents checked for active content

    Macros, DDE fields, remote templates and embedded objects in Office files; scripts, attachments and launch actions in PDFs. Damaged PDFs are refused too.

    oletools, qpdf and PDFiD
  4. 04

    Pictures rebuilt from their pixels

    Profile photos and logos are redrawn as new images, so nothing hidden in the original survives. SVG logos are cleaned.

    Pillow and DOMPurify
  5. 05

    Stored under random names

    Every download checks, each time, that the person asking may see that file.

  6. 06

    Served so nothing runs

    A fixed content type and a policy that lets nothing in the file execute in the browser.

Safe copies of documents from the other side

When a CV reaches a company, or an assignment brief reaches a candidate, the other side can open a safe copy made with Dangerzone: the document turned into pixels and back into a clean PDF, inside an isolated sandbox.

Accepted: PDF, Word (.doc and .docx), Excel, PowerPoint, ZIP, PNG, JPG, WebP and plain text. Read the full guide.

Accounts & access

The right people, and only them.

  • One sign-in per side

    Candidates sign in on hiredec.com, hiring teams on app.hiredec.com. Each sign-in only opens its own side.

  • Confirmed email addresses

    New accounts confirm their email before they can sign in.

  • Password resets sign out

    Resetting a password signs the account out on its other devices.

  • Roles, checked on the server

    Every action a teammate takes is checked against their role, not only hidden in the interface.

  • Not found means not found

    Asking for someone else's application or file looks exactly like asking for one that doesn't exist.

  • Limits on every door

    Requests are rate-limited per user, and sign-in attempts too.

Under the hood

Careful by default.

Access rules are covered by automated tests that try to reach other people's applications, files and actions.

  • A strict content policy

    Each page only runs the scripts it was served with, using a fresh key per request, which blocks injected scripts.

  • Security headers

    Set in one place for every response, with Helmet.

  • Validated input

    Every request is checked against a schema before it's used, and bodies stop being read at their size limit.

  • No third-party images

    Company logos from the web are fetched and checked by our server, so your browser never loads them from elsewhere.

  • Read-only mail connections

    Connecting Gmail or Outlook asks for read-only access, and the tokens are stored encrypted.

  • History that only grows

    Every change to an application is recorded as a new event; nothing is rewritten.

Found something?

Tell us about it.

If you think you've found a security issue, write to us with the details. Please give us a chance to fix it before sharing it publicly.

Report an issue

[email protected]