---
title: "Security overview - JobsPipe"
description: "The security measures JobsPipe maintains, how we notify customers of a breach, and how to report a vulnerability to security@jobspipe.dev under our responsible disclosure rules."
canonical: https://jobspipe.dev/trust/security
---

[NewSearch millions of jobs from your AI agent with MCP→](/blog/jobspipe-mcp-server)

[Trust Center](/trust)

# Security overview

What we do to protect the JobsPipe service and the data customers send us, how we tell you when something goes wrong, and how to report a vulnerability.

Last updated: September 24, 2026

## Measures we maintain

-   Data is encrypted in transit with TLS.
-   Access to production systems is restricted to authorized personnel.
-   Secrets are held outside source code.
-   Live data requires an API key, and every plan carries request rate limits and a monthly row cap.
-   We take daily backups.
-   We run an incident response process, and publish live service health and incident history on our status page.

Our [Data Processing Addendum](/dpa) sets out the measures we commit to by contract; a fuller description is available on request.

## Breach notification

If a personal data breach affects customer data, we notify the affected customers without undue delay, and in any event within 72 hours, as the [Data Processing Addendum](/dpa) commits us to. Service incidents are posted on [https://status.jobspipe.dev](https://status.jobspipe.dev).

## Your account

Keep API keys secret and out of client-side code and public repositories. If a key leaks, revoke it and create a new one in the dashboard. You can delete your account yourself under Settings.

## Responsible disclosure

If you find a vulnerability, email [security@jobspipe.dev](mailto:security@jobspipe.dev). Our [security.txt](/.well-known/security.txt) carries the same contact. Please include:

-   The affected URL, endpoint or MCP tool.
-   Steps to reproduce, with requests and responses where you can.
-   What an attacker could achieve.
-   How we can reach you, and how you would like to be credited, if at all.

## Scope

These hosts are in scope:

-   jobspipe.dev
-   api.jobspipe.dev
-   mcp.jobspipe.dev

Anything else, including the sites we collect job postings from, is out of scope. Ask us first if you are unsure.

## Rules

-   No denial-of-service or volumetric testing, and no automated scanning that degrades the service for others.
-   Do not access, change or delete data that belongs to other customers. Use only accounts you own, and stop as soon as you reach data that is not yours.
-   No social engineering or phishing of JobsPipe staff or customers, and no physical attacks.
-   Give us reasonable time to fix the issue before you disclose it publicly.

Reports are not paid.

## Safe harbour

If you research in good faith and within these rules, we will treat your work as authorized, will not pursue legal action against you for it, and will work with you to understand and fix the issue. If you are unsure whether something is allowed, ask us before you do it.

---
Canonical URL: https://jobspipe.dev/trust/security

---
AI agents: the full machine-readable index of this site is https://jobspipe.dev/llms.txt?src=md-twin - API quickstart, no-key sandbox (POST https://api.jobspipe.dev/v1/sandbox/jobs/search), MCP server, pricing. Free key: https://jobspipe.dev/signup