Protected by design
Security

What's protected, what isn't, and why we'd rather tell you.

Most security pages are adjectives. This one is a list.

Why this page is a list and not a paragraph

"Bank-level security", "enterprise-grade encryption", "your data is safe with us" — these phrases appear on nearly every product website and they contain no information. They are designed to end the question rather than answer it.

A security page is only useful if a reader can come away knowing something specific enough to act on, which means naming what is protected, what isn't, and where the line is. That is what follows. It is less comfortable than the adjective version and it is the only version worth publishing.

// CHiiRO field-level encryption
email_address
given_name
family_name
telephone
date_of_birth
// stored readable — not encrypted
profile_bio
company_name
discussion_text

What is protected, and what isn't

The actual list.

Protected — encrypted at rest

  • Account email address
  • Given and family names
  • Telephone number
  • Date of birth

Not protected — stored readable

  • Free-text profile fields
  • Company and job title
  • Profile picture reference
  • Discussion post text
  • Job application details

Passwords are never stored in a recoverable form.

Messages are not end-to-end encrypted.

Direct messages are not end-to-end encrypted, and the operator can read message content on the server.

We will not use the phrase "secure messaging", because most people read it as end-to-end encryption and it would be wrong here. If end-to-end encryption is a requirement for a particular conversation, have that conversation somewhere built for it.

No professional network we know of states this plainly, and most of them are in the same position.

Certifications

CHiiRO itself holds no security certification. There is no SOC 2 report and no "GDPR certified" badge — that last credential does not exist as a thing anyone can hold, despite appearing in footers across the industry.

Reporting something

If you find a security problem, tell us.

We would rather hear it from you than from someone else. The reporting route is on this page and it goes to somebody who reads it. We won't threaten a researcher who reports in good faith.

We won't promise a bounty we haven't funded, and we won't promise a response time we haven't staffed — but a report will be read by a person and acted on.

Contact

hello@chiiro.co — put "security" in the subject line.

The reporting route goes to somebody who reads it.

What we're working on

This page changes as the product does, and the changes are dated. The gaps named above are gaps we know about and are closing in order of how much they matter, which is not the same order as how bad they look.

A security page that only ever gets better-sounding is one nobody is actually maintaining.

What you get

01

Decide what to type into a free-text field based on facts rather than an adjective.

02

Know before you start a conversation whether it belongs on CHiiRO at all.

03

Report a problem without wondering whether you'll be threatened for it.

04

Read a security page that would be embarrassing if it were vague, and isn't.

Questions and answers

Q.Are CHiiRO direct messages end-to-end encrypted?

No. Messages are not end-to-end encrypted, and the operator can read message content on the server.

Q.What data does CHiiRO encrypt?

Account email address, given and family names, telephone number and date of birth are encrypted where stored. Free-text profile fields, company and job title, discussion text and job application details are not. Passwords are never stored in a recoverable form.

Q.Is CHiiRO SOC 2 compliant?

No. CHiiRO holds no SOC 2 report. It also does not claim "GDPR certified", a credential that does not exist for anyone to hold.

Q.How do I report a security issue to CHiiRO?

Use the reporting route on this page. Reports are read by a person. CHiiRO does not threaten researchers who report in good faith.

Q.Should I put sensitive information in a CHiiRO profile?

Treat free-text fields as readable. CHiiRO publishes exactly which fields are protected and which are not.

Live on Google Play

Report a security issue

We would rather hear it from you than from someone else.