Security

HumanVerified.cv is intended for privacy-conscious and sensitive hiring, so security posture must be plain, bounded and honest.

Data minimisation

The site should not collect CVs, identity documents or sensitive verification material through casual static forms. Real file handling is blocked until secure upload, scanning, access control and retention processes exist.

Access controls

Operational access controls, reviewer permissions and audit trails require owner approval before live verification processing.

Secure transmission

Production must use HTTPS. Apache/LiteSpeed headers are provided in .htaccess, and live header behaviour must be confirmed on the actual host.

File handling policy

Do not send identity documents, DBS certificates, passports or other sensitive documents through general forms. Secure file handling is a launch blocker.

Incident contact

Security and incident contact email requires owner confirmation before launch.

What is not currently offered

No public certification claim is made here. No SC, DV, DBS, statutory right-to-work, ISO, SOC 2 or equivalent certification claim should be inferred unless separately implemented, evidenced and legally reviewed.

No optional cookie preference has been saved yet.

Essential preference storage is always on. Analytics and marketing are off in this build and no optional scripts are loaded.