Connections
The site is served only over HTTPS. Plain-HTTP requests are redirected, and browsers are told to use HTTPS for future visits (HSTS). The server refuses to start in its internet-facing configuration unless secure cookies and a dedicated encryption key are set.
Accounts and sessions
- Passwords are hashed with bcrypt and never stored or logged in plain text.
- Sign-in uses a session cookie that page scripts can't read (HttpOnly), is sent only over HTTPS (Secure), and isn't sent on cross-site requests (SameSite=Lax). Sessions last up to seven days.
- Signing out invalidates that session on the server, not just in your browser.
- “Log out everywhere” and a password change end every other session immediately.
- Sign-in errors are the same for an unknown email and a wrong password, and take the same time, so the form can't be used to find out who has an account.
Access to your data
Every request for a resume or report is checked on the server against the signed-in account. Asking for someone else's resume returns “not found”, so their IDs can't even be confirmed to exist. Administrators can list and delete accounts; there's no feature for reading another user's resumes.
AI provider credentials
The AI provider is configured by the service administrator; there are no AI keys or endpoints in user settings. Provider credentials are encrypted at rest and are never sent to any browser, including the administrator's.
Contact details and AI
Before resume content reaches an AI provider, your name, email, phone, address and profile links are removed. When a file is imported, they're replaced with placeholders and restored on the server afterwards. The privacy policy covers the details, including the rare case where a name in an unusual position isn't detected.
Abuse protection
Sign-in, registration, password changes, AI features and job search are rate-limited per network address and per account. Uploads are checked by content type as well as file extension, and size-limited. Server logs record which routes were used and whether they succeeded, never resume text, AI prompts, passwords or keys.
What we don't claim
No system is perfectly secure, and QuickHunt hasn't had an independent security audit. Resume content is protected by access controls and the security of the server it's stored on, but isn't separately encrypted in the database. And while we care about getting you hired, QuickHunt makes no promises about hiring outcomes; see the terms.
Reporting an issue
If you think you've found a vulnerability, please report it privately: email [email protected]. Include steps to reproduce it. Please don't access or change other people's data, and avoid testing that degrades the service for others.