Skip to main content
Trust

Security Policy

How we protect your account, data and the platform.

Practices

  • TLS 1.2+ in transit; encryption at rest for databases and storage
  • Row-level security on user data; least-privilege service roles
  • Continuous automated security scanning and dependency review
  • Isolated environments for dev, staging and production

Authentication

Password + Google Sign-In, hashed credentials, session rotation and optional 2FA on admin roles.

Account protection

Anomaly detection on sign-ins, device management and immediate revocation on password change.

Fraud prevention

AI moderation on listings and messages, verified employer badges and community reporting.

Responsible disclosure

Report vulnerabilities to security@goh.app. We acknowledge within 48 hours and do not pursue researchers acting in good faith.

Incident response

Documented runbooks, 24/7 on-call and user notification for incidents affecting personal data, in line with applicable law.