Security at Rawminds
Rawminds applies layered controls to protect hiring and account data while the service is in early access. This page states the current security posture without promising that any system is risk-free.
Effective 28 July 2026 · Version 1.1
Current controls
Production traffic uses encrypted transport. Application access is role- and tenant-scoped, secrets are held outside source control, administrative access has additional network and application controls, and durable data is stored in managed databases and object storage.
Operational readiness checks cover critical database, cache, object-storage, and schema dependencies. Backups, encrypted database snapshots, logs, rate limits, and deployment smoke tests support recovery and detection.
Feature isolation
Capabilities that lack a complete production contract—such as semantic search, voice interviews, code execution, or paid checkout—remain disabled or clearly marked preview until their isolation, credentials, monitoring, and end-to-end tests are verified.
Your responsibilities
Use a unique password, protect account and invite links, review workspace membership, and upload only information you are authorized to process. Contact Rawminds promptly if a device, credential, or shared resource may be compromised.
Report a vulnerability
Send a concise report to contact@rawminds.ai with “Security report” in the subject, or use the machine-readable policy at rawminds.ai/.well-known/security.txt. Include the affected surface, reproducible steps, and impact; do not access other users’ data, disrupt service, or publish sensitive details before coordinated review.