Security at StartupWorker
Security is part of how we design the service, handle private member data, and respond when something may be wrong.
Last updated: September 10, 2026Our approach
StartupWorker uses managed authentication, row-level database authorization, least-privilege data access, HTTPS, secure production cookies, request validation, rate limits, dependency checks, and operational response procedures. We minimize the personal information sent to product analytics and keep privileged database credentials out of the application runtime.
No system is perfectly secure. We review safeguards as the product, threats, and legal obligations change.
Report a vulnerability
Email security@startupworker.com with a clear description, the affected URL or feature, steps to reproduce, potential impact, and any supporting screenshots or logs with secrets and personal data removed. Do not send passwords, session tokens, private user data, or working exploit payloads by ordinary email.
Please avoid
- accessing, changing, downloading, or deleting another person’s data;
- disrupting availability, sending spam, or testing denial-of-service conditions;
- social engineering, physical attacks, or testing third-party providers;
- automated scanning that degrades the Service; and
- public disclosure before we have had a reasonable opportunity to investigate and address the issue.
This policy is not a bug-bounty program, a promise of payment, or authorization to access data or systems.
What happens next
We aim to acknowledge useful reports, investigate proportionately to risk, keep the reporter informed when practical, and address verified issues. We will follow applicable notification obligations if an incident affects personal information.