Why this page is a list and not a paragraph
"Bank-level security", "enterprise-grade encryption", "your data is safe with us" — these phrases appear on nearly every product website and they contain no information. They are designed to end the question rather than answer it.
A security page is only useful if a reader can come away knowing something specific enough to act on, which means naming what is protected, what isn't, and where the line is. That is what follows. It is less comfortable than the adjective version and it is the only version worth publishing.
What is protected, and what isn't
The actual list.
Protected — encrypted at rest
- Account email address
- Given and family names
- Telephone number
- Date of birth
Not protected — stored readable
- Free-text profile fields
- Company and job title
- Profile picture reference
- Discussion post text
- Job application details
Passwords are never stored in a recoverable form.
Certifications
CHiiRO itself holds no security certification. There is no SOC 2 report and no "GDPR certified" badge — that last credential does not exist as a thing anyone can hold, despite appearing in footers across the industry.
Reporting something
If you find a security problem, tell us.
We would rather hear it from you than from someone else. The reporting route is on this page and it goes to somebody who reads it. We won't threaten a researcher who reports in good faith.
We won't promise a bounty we haven't funded, and we won't promise a response time we haven't staffed — but a report will be read by a person and acted on.
Contact
hello@chiiro.co — put "security" in the subject line.
The reporting route goes to somebody who reads it.
What we're working on
This page changes as the product does, and the changes are dated. The gaps named above are gaps we know about and are closing in order of how much they matter, which is not the same order as how bad they look.
A security page that only ever gets better-sounding is one nobody is actually maintaining.
What you get
Decide what to type into a free-text field based on facts rather than an adjective.
Know before you start a conversation whether it belongs on CHiiRO at all.
Report a problem without wondering whether you'll be threatened for it.
Read a security page that would be embarrassing if it were vague, and isn't.
Questions and answers
Q.Are CHiiRO direct messages end-to-end encrypted?
No. Messages are not end-to-end encrypted, and the operator can read message content on the server.
Q.What data does CHiiRO encrypt?
Account email address, given and family names, telephone number and date of birth are encrypted where stored. Free-text profile fields, company and job title, discussion text and job application details are not. Passwords are never stored in a recoverable form.
Q.Is CHiiRO SOC 2 compliant?
No. CHiiRO holds no SOC 2 report. It also does not claim "GDPR certified", a credential that does not exist for anyone to hold.
Q.How do I report a security issue to CHiiRO?
Use the reporting route on this page. Reports are read by a person. CHiiRO does not threaten researchers who report in good faith.
Q.Should I put sensitive information in a CHiiRO profile?
Treat free-text fields as readable. CHiiRO publishes exactly which fields are protected and which are not.
