Trust Center

Trust is foundational to how Jobma operates. Our platform is designed with layered safeguards to protect your data, support responsible AI use, and meet global compliance requirements, so you can hire with confidence.

Controls

Legal

  • Data Processing Agreement
  • Privacy Policy
  • Terms of Service

Corporate Security

  • Employee Training
  • Incident Response
  • Internal Assessments

Access Control

  • Password Security
  • Data Access
  • Logging

Network Security

  • Data Loss Prevention

Infrastructure

  • Google Cloud
  • BC/DR

App Security

  • Vulnerability & Patch Management
  • Credential Management
  • Software Development Lifecycle

Data Security

  • Backups Enabled
  • Data Erasure
  • Access Monitoring

Product Security

  • Role-Based Access Control
  • Single Sign-On
  • Audit Logging

Policies

  • Risk Management Policy
  • Software Development Lifecycle
  • Password Policy

Reports

  • Vulnerability Assessment Report
  • Pentest Report
  • Network Diagram

AI Trust & Security

  • Artificial Intelligence Management System

Sub-Processors

View All
Jobma continuously monitors, reviews, and updates its security practices to align with evolving standards and customer expectations. If you'd like to review our latest policy documents and compliance reports, please contact our security team at privacy@jobma.com .

Controls

Legal

Data Processing Agreement

We have a Data Processing Agreement in place that outlines the data protection obligations applicable when processing customer and candidate information on behalf of our clients. It defines responsibilities related to data handling, retention, security safeguards, and breach notification in alignment with applicable data protection laws.

Privacy Policy

Our Privacy Policy explains how Jobma collects, uses, stores, and protects personal information across our website and hiring platform. It details our data practices for customers, candidates, and business representatives, including transparency around data rights and processing activities.

Terms of Service

Service-Level Agreement

We maintain Service-Level Agreements that define system availability commitments, performance standards, and support response timelines. These agreements establish operational expectations and service reliability benchmarks for our customers.

Controls

Corporate Security

Employee Training

We regularly conduct information security and data privacy training for all employees to maintain compliance and reinforce a culture of security awareness.

Incident Response

We maintain documented incident response policies and procedures to guide timely identification, reporting, investigation, and resolution of security incidents.

Internal Assessments

We perform regular internal audits and risk assessments to evaluate the effectiveness of our security controls and align with recognized industry standards.

Controls

Access Control

Password Security

Password settings are made available in accordance with Jobma's password policy, including complexity, rotation, and reuse restrictions.

Data Access

Access to Jobma systems and customer data is provisioned based on the principle of least privilege and requires prior authorization. Role-based access controls are used to segregate access levels, with database access restricted to authorized admin users via MFA.

Logging

System logs are generated for user access and platform activity to support monitoring and accountability. Logs are securely stored, regularly reviewed, and protected by strict access controls.

Controls

Network Security

Data Loss Prevention

Jobma uses controls to monitor and prevent unauthorized data transfer across its network, helping protect sensitive information from unintended exposure.

Controls

Infrastructure

Google Cloud

Jobma's infrastructure is hosted on Google Cloud Platform. Access controls, storage, and compute resources are managed in alignment with industry security best practices.

BC/DR

Business continuity and disaster recovery plans are documented, maintained, and reviewed on a regular basis to ensure operational resilience. Recovery procedures are tested periodically to validate defined recovery objectives and minimize service disruption in the event of an incident.

Controls

App Security

Vulnerability & Patch Management

Jobma conducts regular vulnerability assessments and testing to identify common web application risks, with high-priority issues resolved promptly.

Credential Management

Access credentials and sensitive secrets are securely stored and managed using approved secret management solutions. Access to credentials is restricted based on role and monitored to prevent unauthorized use or exposure.

Software Development Lifecycle

We implement a Software Development Lifecycle Policy as per standard controls.

Controls

Data Security

Backups Enabled

Periodic backups in place to ensure data availability and resilience. Cross-region backups are maintained to support recovery within defined recovery time objectives in the event of a system failure.

Data Erasure

Customer data is retained in accordance with defined data retention policies and contractual obligations. Data deletion can be made on request.

Access Monitoring

User access to systems and critical applications is regularly reviewed to ensure alignment with the least privilege principle and prevent unauthorized use.

Encryption-in-transit

Data transmitted over public and private networks is encrypted using SSL/TLS protocols.

Encryption-at-rest

Databases and storage systems are configured to enable encryption at rest to protect all video interviews, candidate information, and recruiter communications from interception or tampering.

Controls

Product Security

Role-Based Access Control

Access permissions can be defined for every user, ensuring individuals only view and manage specific data. This enforces least-privilege access and reduces the risk of unauthorized exposure.

Single Sign-On

Jobma supports Single Sign-On through Microsoft and Google as a login mechanism for seamless account access.

Audit Logging

Logs are securely maintained to support monitoring, investigations, and compliance requirements.

Multi-factor Authentication

We support time-based one-time passwords through authenticator applications such as Google Authenticator and Microsoft Authenticator, as well as MFA enforced through supported identity providers to prevent unauthorized access.

Team Management

Users can manage teams and control access at a granular level from a centralized dashboard. This ensures structured collaboration while maintaining security controls.

Service-Level Agreement

Integrations

Controls

Policies

Risk Management Policy

Software Development Lifecycle

Password Policy

Data Classification Policy

Business Continuity Policy

Encryption Policy

Access Control Policy

Backup Policy

Asset Management Policy

Anti-Malicious Software Policy

Internal and External Communication Policy

Data Security Policy

Network Security Policy

ISMS Policy

Information Security Policy

Acceptable Use Policy

Controls

Reports

Vulnerability Assessment Report

Pentest Report

Network Diagram

Controls

AI Trust & Security

Artificial Intelligence Management System

Jobma's AI Management System establishes governance, risk, and compliance controls across all AI-driven hiring features. It ensures transparency, fairness, data protection, and continuous monitoring to align with evolving regulatory and ethical standards.

Sub-Processors

Google Cloud
MySql
IP Stack
Sentry
Zoho SalesIQ
Twillo
Microsoft Clarity
HubSpot