Job Opportunities API

Check the data. Then trust it.

Security and data protection

What we actually do, consolidated from /privacy, /terms and the AI disclosure into one page a procurement review can point at. Nothing here is a new claim — every sentence is already published elsewhere on this site.

The data itself

  • The ledger holds no personal data: a job row names a company, not a person. There are no candidates, no applications, no CVs and no jobseeker accounts.
  • Account data is limited to an email address and, for API access, a SHA-256 hash of your secret — never the secret itself, so a stolen database yields no working keys.

In transit and at rest

  • Everything travels over HTTPS. The site and the API refuse plain HTTP, and certificates are renewed automatically.
  • Card details never reach our servers at any point. Payment happens on Creem’s own hosted page, our Merchant of Record; we receive only the outcome and an order reference.
  • Access to the production database is limited to the operator, over an authenticated tunnel, and is not exposed to the public internet.
  • Backups are encrypted and kept off the machine that made them.

If something goes wrong

  • If personal data of yours is ever exposed, we will tell you and the Hellenic Data Protection Authority within 72 hours of finding out, as the GDPR requires — even if the number of affected people is small.
  • No formal SLA exists today; see /status for what is measured and how to ask for one.

Who else processes it

  • Cloudflare — serves the site, and runs the bot check that keeps scrapers out.
  • Lettermint — sends our email.
  • Mistral AI, Cloudflare Workers AI, Hetzner (hosted inference), Alibaba Cloud (fallback only) and Venice AI — classify job titles, tell employers from agencies and read employers' public careers pages, from text employers published themselves, never your account data.
  • Creem (creem.io) — our Merchant of Record. It takes the card payment, calculates and collects VAT, and issues the invoice. We never see the card number or your billing details.
  • PostHog — records account events (signing in, subscribing, checking out, writing to us), against your email address, on their EU infrastructure. No analytics script runs in your browser.

Reporting a vulnerability

  • Email [email protected] — monitored by Loukas Tzekos, the operator. Also published, machine-readable, at /.well-known/security.txt (RFC 9116).
  • Please include: what you found, the steps to reproduce it, the impact as you see it, and (if useful) a proof-of-concept request/response — enough to reproduce it without back-and-forth, but nothing beyond what is needed to demonstrate the issue.
  • We acknowledge every report within 3 business days.
  • Remediation targets once a report is confirmed: critical severity within 7 days, high severity within 30 days. We will tell you when it is fixed.
  • We will not pursue legal action against good-faith security research that follows this policy: testing only your own account/data, not degrading the service for other users, and reporting privately here before any public disclosure.
  • There is no bounty program today. We are happy to credit you publicly if you would like that.

Full detail: Privacy, Terms (VAT and invoicing, handled by Creem as Merchant of Record) and the AI disclosure. Live freshness and uptime measurement: /status. A question a procurement review needs answered that is not here? Ask us.