Security & privacy
Every file checked.
Each side private.
Hiring means sharing personal details and opening files from people you don't know yet. Here's how HireDec. keeps both safe, in plain words.
- It's a PDF, as its name saysfile-type
- No malware foundClamAV
- No scripts, attachments or launch actionsqpdf · PDFiD
- Stored under a random name
- Safe copy ready for the companyDangerzone
Between the two sides
One application. Two private sides.
Candidates and hiring teams work on the same application. What each side keeps for itself never crosses over.
Only the candidate sees
- Their private notes and to-dos
- Their interview preparation notes
- The labels they give their CVs
- The names of their profiles
- Their applications to other companies
Both sides see
- The job's stages, and where the application is
- The profile and CV that were sent, as they were then
- Interview times, assignments and their files
- Messages, offers and decisions
Only the hiring team sees
- The team's internal notes about a candidate
- Its other candidates
- Its team, roles and invitations
Every uploaded file
Checked before it's stored. Served so it can't run.
CVs, assignment briefs, hand-ins, photos and logos all go through the same steps. We rely on established open-source tools instead of writing our own detection.
- 01
What it really is
The type comes from the file's content, never its name. Content that doesn't match its name is refused, as is any kind we don't take.
file-type - 02
Scanned for malware
Every upload is scanned before it's stored. If the scanner can't be reached, the upload is refused rather than let through.
ClamAV - 03
Documents checked for active content
Macros, DDE fields, remote templates and embedded objects in Office files; scripts, attachments and launch actions in PDFs. Damaged PDFs are refused too.
oletools, qpdf and PDFiD - 04
Pictures rebuilt from their pixels
Profile photos and logos are redrawn as new images, so nothing hidden in the original survives. SVG logos are cleaned.
Pillow and DOMPurify - 05
Stored under random names
Every download checks, each time, that the person asking may see that file.
- 06
Served so nothing runs
A fixed content type and a policy that lets nothing in the file execute in the browser.
Safe copies of documents from the other side
When a CV reaches a company, or an assignment brief reaches a candidate, the other side can open a safe copy made with Dangerzone: the document turned into pixels and back into a clean PDF, inside an isolated sandbox.
Accepted: PDF, Word (.doc and .docx), Excel, PowerPoint, ZIP, PNG, JPG, WebP and plain text. Read the full guide.
Accounts & access
The right people, and only them.
One sign-in per side
Candidates sign in on hiredec.com, hiring teams on app.hiredec.com. Each sign-in only opens its own side.
Confirmed email addresses
New accounts confirm their email before they can sign in.
Password resets sign out
Resetting a password signs the account out on its other devices.
Roles, checked on the server
Every action a teammate takes is checked against their role, not only hidden in the interface.
Not found means not found
Asking for someone else's application or file looks exactly like asking for one that doesn't exist.
Limits on every door
Requests are rate-limited per user, and sign-in attempts too.
Under the hood
Careful by default.
Access rules are covered by automated tests that try to reach other people's applications, files and actions.
A strict content policy
Each page only runs the scripts it was served with, using a fresh key per request, which blocks injected scripts.
Security headers
Set in one place for every response, with Helmet.
Validated input
Every request is checked against a schema before it's used, and bodies stop being read at their size limit.
No third-party images
Company logos from the web are fetched and checked by our server, so your browser never loads them from elsewhere.
Read-only mail connections
Connecting Gmail or Outlook asks for read-only access, and the tokens are stored encrypted.
History that only grows
Every change to an application is recorded as a new event; nothing is rewritten.
Found something?
Tell us about it.
If you think you've found a security issue, write to us with the details. Please give us a chance to fix it before sharing it publicly.