Security
How Sidedoor protects your resume, your credentials and your sending — and how to report a vulnerability.
LAST UPDATED 12 SEPTEMBER 2026
Infrastructure
- TLS 1.2+ on everything in transit, AES-256 at rest for databases and uploaded files.
- Hosting on providers with SOC 2 Type II compliance, in access-controlled regions.
- Isolated environments: production data never leaves production, and never appears in development or test.
- Daily encrypted backups with restores exercised on a schedule.
Access
- Least privilege, granted per role and reviewed quarterly.
- Mandatory two-factor authentication for every internal system.
- Passwords stored hashed with a modern memory-hard algorithm — we cannot read yours.
- Every production access is logged and the logs are retained.
Application
- Dependencies scanned continuously; security patches applied on a defined clock.
- Code review required on every change that touches auth, billing or user data.
- Rate limits and abuse detection on sending, so a compromised account cannot be turned into a spam cannon.
Your part
Use a unique password, keep your email account secure, and tell us straight away if you think someone else is in your account.
Reporting a vulnerability
Email support@usesidedoor.com with the details and, if you can, a proof of concept. We acknowledge within 2 business days and keep you updated until it is fixed. Test only against your own account, do not access or alter anyone else's data, and do not run denial-of-service or social engineering. Researchers who follow that will not face legal action from us.