Security & privacy

Built like the people in it might read it

Sourcing touches personal data. Jorbit is designed around PIPEDA and the provincial acts: minimal collection, purpose-bound use, and the right to be forgotten honoured for real.

Where your data lives

Hosted in Toronto
Application and database run on DigitalOcean in Canada, with encrypted connections and encrypted storage.
Secrets stay secret
Mailbox and integration credentials are encrypted at rest with a key that never leaves the server. API tokens are stored hashed and shown once.
Backups
Daily managed database backups with point-in-time recovery.

Candidate privacy

Public sources only
Profiles come from public professional pages. Contact details are looked up only when you ask, and only then cost credits.
Erasure everywhere
A person who asks to be removed is deleted from the index and blocked from ever being re-imported, across every workspace.
Do-not-contact
Organisation-wide lists (people, companies, countries) that block reveals and outreach. Removal can be restricted to admins.
Consent-aware outreach
Unsubscribe links, enforced footers, sending limits and bounce handling are organisation controls, not individual choices.

Your organisation

SSO
OpenID Connect or SAML 2.0 with any identity provider; enforce it for everyone.
SCIM 2.0
Provision and deprovision people from Okta, Entra or Google automatically.
Audit log
Who searched, revealed, exported, changed settings, and when. Exportable.
Retention
Automatic deletion of activity, reveals and exports after a period you choose.
Roles
Admins, members and review-only hiring managers; private projects; export permissions per member.
Privacy requests (access, correction, erasure): [email protected]. Security questions or a questionnaire for procurement: [email protected]. Already a customer? Everything above is in Settings → Security.