Legal

Security

How Role Match protects the product and your data.

Last updated: July 26, 2026

Practices

  • HTTPS encryption in transit for the public site and APIs.
  • Session-based authentication with protected admin routes for operators.
  • Database hosted on managed PostgreSQL with access limited to the application and authorized operators.
  • Cron and operational endpoints require a shared secret (Bearer token) and fail closed if misconfigured.
  • Chat and guest ownership checks so users cannot access another person’s conversations.
  • Rate limiting on sensitive API routes to reduce abuse.

Listing data

Shared job listings are imported from public employer sources. We protect our systems and your account data; employer ATS security remains the employer’s responsibility once you leave Role Match to apply.

Your responsibilities

Keep your login credentials private. Sign out on shared devices. Do not paste secrets or sensitive documents into AI chat unless you accept that they may be processed by AI providers.

Report a vulnerability

If you believe you found a security issue on https://rolematch.online, email support@rolematch.online with a clear description. Please do not publicly disclose until we have had a reasonable chance to investigate and fix.

Security | Role Match