This page describes the current product controls at a high level without publishing secrets, internal tokens or exploit details.
Private product data is protected with authenticated routes and database row-level security. Privileged database implementations are kept out of normal API access where practical.
ClockIN supports authentication assurance checks and MFA-sensitive flows for protected recruiter actions. Password and identity controls also depend on the underlying authentication platform configuration.
Interview camera and screen recordings are stored in a private Supabase Storage bucket. Review surfaces use time-limited signed URLs rather than permanent public media links.
The free ATS + Tools service intentionally works without login. Resume and JD content is processed for the request and is not inserted into the public-tools database ledger. The ledger stores only short-lived abuse counters.
Public-source verification validates challenge ownership and protects fetches against local or private network targets. Project Defence is a separate understanding signal.
Integrity signals and competence evidence are kept conceptually separate. ClockIN recommendations are designed to support human review rather than silently make a final employment decision.
If you believe you found a security issue, email info@goclockin.com with a clear description and enough reproduction detail for us to investigate. Please avoid accessing data that is not yours, disrupting the service, or publishing sensitive exploit details before we can review the report.