Security & privacy
Built like the people in it might read it
Sourcing touches personal data. Jorbit is designed around PIPEDA and the provincial acts: minimal collection, purpose-bound use, and the right to be forgotten honoured for real.
Where your data lives
- Hosted in Toronto
- Application and database run on DigitalOcean in Canada, with encrypted connections and encrypted storage.
- Secrets stay secret
- Mailbox and integration credentials are encrypted at rest with a key that never leaves the server. API tokens are stored hashed and shown once.
- Backups
- Daily managed database backups with point-in-time recovery.
Candidate privacy
- Public sources only
- Profiles come from public professional pages. Contact details are looked up only when you ask, and only then cost credits.
- Erasure everywhere
- A person who asks to be removed is deleted from the index and blocked from ever being re-imported, across every workspace.
- Do-not-contact
- Organisation-wide lists (people, companies, countries) that block reveals and outreach. Removal can be restricted to admins.
- Consent-aware outreach
- Unsubscribe links, enforced footers, sending limits and bounce handling are organisation controls, not individual choices.
Your organisation
- SSO
- OpenID Connect or SAML 2.0 with any identity provider; enforce it for everyone.
- SCIM 2.0
- Provision and deprovision people from Okta, Entra or Google automatically.
- Audit log
- Who searched, revealed, exported, changed settings, and when. Exportable.
- Retention
- Automatic deletion of activity, reveals and exports after a period you choose.
- Roles
- Admins, members and review-only hiring managers; private projects; export permissions per member.
Privacy requests (access, correction, erasure): [email protected]. Security questions or a questionnaire for procurement: [email protected]. Already a customer? Everything above is in Settings → Security.