Security approach
TrustBee uses layered safeguards appropriate to a role-based recruitment platform. Security is an ongoing risk-management process, not a guarantee that incidents can never occur.
Platform controls
Verified controls include managed authentication, server-side authorisation, role checks, row-level database access rules, private application-CV storage, time-limited CV access, input validation, bot protection on sensitive forms and controlled administrator functions.
Your responsibilities
Use a strong unique password, protect your email account, sign out from shared devices and report suspicious activity promptly. Do not share access tokens, passwords or invitation links. TrustBee does not currently claim to offer two-factor authentication.
Safe data handling
Recruiters and providers must protect information they lawfully receive and limit access to authorised staff. Job seekers should avoid including unnecessary sensitive information in profiles, CVs, messages or AI prompts.
Incident response
We investigate credible security and privacy incidents, contain risks, preserve relevant evidence and notify affected people or authorities when required by applicable law. Details may be limited while an investigation is active.
Responsible disclosure
Report suspected vulnerabilities privately to kontakt@trustbee.se with clear reproduction steps and no unnecessary personal data. Do not exploit a vulnerability, access other users’ data, disrupt the service or publish details before we have had a reasonable opportunity to investigate.
No absolute guarantee
No online service is completely secure. This Policy describes safeguards visible in the current platform; it is not a certification, audit opinion, warranty or promise of immunity from attack.