Security
HumanVerified.cv is intended for privacy-conscious and sensitive hiring, so security posture must be plain, bounded and honest.
Data minimisation
The site should not collect CVs, identity documents or sensitive verification material through casual static forms. Real file handling is blocked until secure upload, scanning, access control and retention processes exist.
Access controls
Operational access controls, reviewer permissions and audit trails require owner approval before live verification processing.
Secure transmission
Production must use HTTPS. Apache/LiteSpeed headers are provided in .htaccess, and live header behaviour must be confirmed on the actual host.
File handling policy
Do not send identity documents, DBS certificates, passports or other sensitive documents through general forms. Secure file handling is a launch blocker.
Incident contact
Security and incident contact email requires owner confirmation before launch.
What is not currently offered
No public certification claim is made here. No SC, DV, DBS, statutory right-to-work, ISO, SOC 2 or equivalent certification claim should be inferred unless separately implemented, evidenced and legally reviewed.