Skip to main content
Trust
Security Policy
How we protect your account, data and the platform.
Practices
- TLS 1.2+ in transit; encryption at rest for databases and storage
- Row-level security on user data; least-privilege service roles
- Continuous automated security scanning and dependency review
- Isolated environments for dev, staging and production
Authentication
Password + Google Sign-In, hashed credentials, session rotation and optional 2FA on admin roles.
Account protection
Anomaly detection on sign-ins, device management and immediate revocation on password change.
Fraud prevention
AI moderation on listings and messages, verified employer badges and community reporting.
Responsible disclosure
Report vulnerabilities to security@goh.app. We acknowledge within 48 hours and do not pursue researchers acting in good faith.
Incident response
Documented runbooks, 24/7 on-call and user notification for incidents affecting personal data, in line with applicable law.