Recruitment operating system
Trust & Security
Last reviewed 2026-07-12 · Questions: hamzah@vrsjo.com
Official application boundary
The credentialed VRS Recruit application is served at app.vrsjo.com. Authentication, callbacks, generated application links, and credentialed browser API access use this service-bound origin rather than the hostname supplied by a request.
VRS Recruit does not use company-slug product hosts. Customer-owned careers domains expose public recruitment resources only and never become sign-in, cookie, or credentialed API authorities.
Identity and request controls
- First-party authentication uses product-bound relying-party identity, cookie namespace, and public origin configuration.
- Protected requests reload the authenticated session and active workspace membership before tenant-owned data is used.
- Product, edition, workspace, and public-resource mismatches fail closed before the protected handler runs.
- Public edge services strip untrusted forwarding headers and use signed internal host proof where an origin must recover visitor authority.
Data and operational controls
- Transport is HTTPS at the public edge; application services are deployed as explicit product-bound runtimes.
- Tenant-owned records carry tenant or workspace scope, and sensitive mutations pass through scoped authorization checks and audit paths.
- Provider credentials and edge proof material are secret bindings; they are not embedded in client bundles or public configuration.
- Readiness checks validate the runtime product, tier, host proof, and critical configuration before a candidate may receive traffic.
Privacy and legal
Review the current privacy notice and terms of service. A data processing addendum is also available. Product or procurement questions can be sent through the official support channel.
The third-party providers that process personal data on our behalf are listed on the sub-processors page. Product analytics are processed in the European Union, and nothing is collected in your browser until you accept the analytics banner — see the privacy notice for what is and is not collected.
Report a security issue
Send responsible disclosures to hamzah@vrsjo.com. Do not include passwords, session tokens, private keys, or unnecessary personal data.