We take security seriously. This page outlines our security practices and how to report vulnerabilities.
All data transmitted to and from Interview Resources is encrypted using TLS 1.3. At rest, sensitive data is encrypted using AES-256 encryption.
We use industry-standard OAuth 2.0 for authentication via Google. Session tokens are securely managed and expire after reasonable inactivity periods.
Our database is hosted on Neon (PostgreSQL) with built-in security features including row-level security, encrypted connections, and automatic backups.
All payment processing is handled by Dodo Payments, a PCI DSS compliant payment provider. We never store credit card information on our servers.
We regularly review and update our security practices. Our infrastructure is hosted on Vercel, which provides additional layers of security and DDoS protection.
If you discover a security vulnerability, please report it responsibly to security@interviewresources.app. We appreciate responsible disclosure and will work with you to address any issues promptly.
In the event of a security incident, we have procedures in place to respond quickly and transparently. Affected users will be notified promptly in accordance with applicable laws and regulations.