Security

We take security seriously. This page outlines our security practices and how to report vulnerabilities.

Data Encryption

All data transmitted to and from Interview Resources is encrypted using TLS 1.3. At rest, sensitive data is encrypted using AES-256 encryption.

Authentication

We use industry-standard OAuth 2.0 for authentication via Google. Session tokens are securely managed and expire after reasonable inactivity periods.

Database Security

Our database is hosted on Neon (PostgreSQL) with built-in security features including row-level security, encrypted connections, and automatic backups.

Payment Security

All payment processing is handled by Dodo Payments, a PCI DSS compliant payment provider. We never store credit card information on our servers.

Regular Security Audits

We regularly review and update our security practices. Our infrastructure is hosted on Vercel, which provides additional layers of security and DDoS protection.

Reporting Vulnerabilities

If you discover a security vulnerability, please report it responsibly to security@interviewresources.app. We appreciate responsible disclosure and will work with you to address any issues promptly.

Incident Response

In the event of a security incident, we have procedures in place to respond quickly and transparently. Affected users will be notified promptly in accordance with applicable laws and regulations.