Security & Trust
Last updated: 8 July 2026
Security is foundational at Skilyo. This page summarises how we protect your data — for candidates, employers and enterprise buyers reviewing us.
How we protect data
- Encryption in transit: all traffic is served over HTTPS/TLS with HSTS enforced.
- Strong authentication: passwords are stored only as salted bcrypt hashes; sessions use signed, httpOnly cookies; login is rate-limited against brute force.
- Hardened application: a strict Content-Security-Policy, X-Frame-Options, nosniff and related headers; input validation and parameterised database queries throughout.
- Payments: processed by Razorpay (PCI-DSS compliant). Skilyo never sees or stores your card or bank details.
- Résumés & profiles: résumé downloads are access-controlled to the relevant employer; public pages never expose candidate email addresses.
- Least privilege & monitoring: restricted access to production, dependency vulnerability scanning, and server-side error logging.
- Backups: the database and résumés are backed up on a regular schedule.
Verification integrity
Skill assessments are timed and integrity-monitored with anti-cheating checks (tab-switch and paste detection, randomised questions). This protects the meaning of the Verified badge.
Compliance roadmap
We follow India’s DPDP Act 2023 and UK/EU GDPR, and are working toward SOC 2 and ISO 27001. A Data Processing Addendum and sub-processor list are available.
Responsible disclosure
Found a vulnerability? Please email sanket@hridtech.com with details. We will acknowledge and work with you to resolve it, and we will not pursue good-faith researchers.