Security Policy

Effective Date: July 2026 | Last Updated: July 2026

1. Purpose and Scope

This Security Policy explains the measures Career Agent (Pty) Ltd uses to protect information processed through the Career Agent mobile application, website, employer dashboard, recruitment platform, application programming interfaces, and related services collectively referred to as the "Services".

The Policy applies to Career Agent's systems, employees, contractors, authorised service providers, and other persons who may access information or infrastructure used to provide the Services.

Our security programme is designed to protect the confidentiality, integrity, and availability of personal information, candidate records, organisation data, account information, and other information processed through the Services.

2. Security Governance

Career Agent assigns responsibility for information security, privacy compliance, access management, risk assessment, and incident response to authorised personnel.

Security responsibilities include:

  • maintaining appropriate security policies and procedures;
  • identifying and assessing technical, operational, and privacy risks;
  • controlling access to systems and personal information;
  • monitoring suspicious activity and security events;
  • reviewing third-party providers that process information on our behalf;
  • coordinating the investigation and response to security incidents.

3. Technical Security Measures

Career Agent implements reasonable technical safeguards based on the nature of the Services, the information processed, and the risks associated with unauthorised access, loss, disclosure, alteration, or destruction.

These safeguards may include:

  • encryption of information in transit using HTTPS and industry-standard transport security;
  • encryption of sensitive information at rest where appropriate;
  • secure authentication, session management, and account access controls;
  • role-based access controls and least-privilege access for staff, systems, and organisation users;
  • network firewalls, server hardening, traffic filtering, and restricted administrative access;
  • logging, monitoring, rate limiting, and detection of suspicious or unauthorised activity;
  • vulnerability management, security updates, and remediation of identified risks;
  • secure backups, recovery procedures, and measures intended to support service continuity.

4. Application and Platform Security

Security controls apply to both the Career Agent mobile application used by candidates and the hiring system used by employers and recruiters.

We take reasonable steps to:

  • protect candidate profiles, CVs, application records, uploaded documents, and account information;
  • restrict employer and recruiter access to authorised organisation accounts and assigned user roles;
  • separate access between organisations so that users cannot access another organisation's recruitment information without authorisation;
  • validate and control file uploads, application requests, and system inputs;
  • protect application interfaces against unauthorised access, abuse, excessive requests, and common security threats;
  • review production changes and restrict access to deployment and administrative systems.

No application, network, or electronic storage system can be guaranteed to be completely secure. Career Agent therefore does not warrant that the Services will be free from every security threat or unauthorised attempt.

5. Access Control and Account Security

Access to Career Agent systems and information is limited to authorised persons who require access for legitimate business, technical, support, security, or recruitment purposes.

Career Agent may use authentication controls, access permissions, account verification, session expiry, login monitoring, and additional verification measures where appropriate.

Organisations are responsible for managing access to their hiring accounts, assigning appropriate user roles, and promptly removing access for employees, recruiters, contractors, or administrators who are no longer authorised.

Users must not share account credentials with unauthorised persons or attempt to access information outside the permissions granted to their accounts.

6. Organisational and Operational Measures

Career Agent maintains operational procedures intended to reduce security and privacy risks.

These measures may include:

  • confidentiality and security obligations for employees and contractors;
  • security awareness and responsible handling of personal information;
  • controlled access to production systems and administrative tools;
  • software review, testing, change management, and deployment controls;
  • security logging, investigation, and retention of relevant records;
  • periodic review of access rights, service providers, and material security risks.

7. Data Minimisation and Retention

Career Agent seeks to collect and process only the information reasonably required to provide, secure, maintain, and improve the Services or to comply with legal obligations.

Information is retained only for as long as reasonably necessary for the purposes for which it was collected, including service delivery, account administration, fraud prevention, legal compliance, dispute resolution, security investigations, and enforcement of agreements.

Information that is no longer required may be deleted, de-identified, anonymised, or securely disposed of in accordance with our retention practices and applicable law.

Additional information about collection, processing, retention, and deletion is available in the Career Agent Privacy Policy.

8. Third-Party Service Providers

Career Agent may use third-party providers for cloud hosting, authentication, communications, artificial intelligence, payment processing, analytics, monitoring, document processing, and other operational services.

Where a provider processes information on our behalf, we take reasonable steps to assess the provider and require appropriate confidentiality, privacy, and security obligations.

Third-party providers remain responsible for the security of systems and services under their control. Career Agent cannot guarantee that a third-party provider will never experience a security incident, service failure, or unauthorised attack.

9. Security Incident Response

Career Agent maintains procedures for identifying, assessing, containing, investigating, and responding to actual or suspected security incidents.

Depending on the nature of an incident, we may:

  • restrict or suspend affected systems or accounts;
  • investigate the cause, scope, and potential impact of the incident;
  • preserve relevant records and take steps to prevent further unauthorised access;
  • restore affected services and implement appropriate corrective measures;
  • notify affected individuals, organisations, regulators, or authorities where required by applicable law.

Notification will be provided in accordance with applicable legal requirements and may depend on the nature of the information, the level of risk, and the findings of the investigation.

10. User and Organisation Responsibilities

Security is a shared responsibility. Candidates, recruiters, employers, and organisation administrators must take reasonable steps to protect their accounts and devices.

Users and Organisations must:

  • use strong and unique account credentials;
  • protect login details, verification codes, and account recovery information;
  • keep devices, operating systems, browsers, and applications reasonably updated;
  • avoid accessing Career Agent through compromised, shared, or unsecured devices where sensitive information may be exposed;
  • review account permissions and remove unauthorised organisation users promptly;
  • verify suspicious messages, links, payment requests, job offers, and account notifications;
  • immediately report suspected account compromise, phishing, data misuse, or unauthorised access;
  • comply with the Acceptable Use Policy, Terms of Service, and, where applicable, the Organisation Policy.

Career Agent is not responsible for losses caused by a user's failure to protect account credentials, devices, or information, except where liability cannot lawfully be excluded.

11. Vulnerability Reporting

Security researchers and users who identify a suspected vulnerability should report it responsibly and must not exploit the issue, access information without authorisation, disrupt the Services, or publicly disclose the vulnerability before Career Agent has had a reasonable opportunity to investigate and respond.

Reports should include sufficient technical information to help us understand and reproduce the issue.

Email: info@careeragentapp.co.za

12. Review and Updates

Career Agent may review and update this Security Policy to reflect changes in the Services, technology, legal requirements, security risks, and business practices.

Material changes may be communicated through the mobile application, website, hiring platform, or email where appropriate.

© Career Agent (Pty) Ltd