Candidates Think Your Recruiter Is Fake. Prove You're Real.
Job scams made candidates distrust real recruiters too. Here's the data, and the trust infrastructure that proves your outreach is legit, not a scam.
Notes on hiring, security, and how we build Kit.
Job scams made candidates distrust real recruiters too. Here's the data, and the trust infrastructure that proves your outreach is legit, not a scam.
Microsoft threatened a researcher with criminal charges, then backtracked in days. Here's how safe harbor in your vulnerability disclosure policy prevents that.
The Mercor breach exposed 4TB of candidate SSNs, passports, and video interviews. Here is why your ATS is a prime target and the privacy-by-design controls that shrink the blast radius.
CRA reporting starts on 11 September 2026 for manufacturers in scope. The main obligations, including coordinated vulnerability disclosure, apply from 11 December 2027.
HackerOne cut Internet Bug Bounty rewards up to 89% on work already done. Here's how to set bug bounty tiers that survive AI slop without betraying researchers.
The North Korean IT worker scheme nets an estimated $250M-$600M a year by placing fake remote hires inside U.S. companies. Here's how to catch them at intake.
curl, HackerOne, and Nextcloud all buckled under AI-generated bug bounty slop in 2026. Here's the triage playbook that keeps a VDP alive under volume.
Researchers don't drop zero-days because they're hostile. They publish after slow acks, silent fixes, and severity downgrades. Keep them coordinating with you.
Connect hiring, training, and access records so your team can reconstruct onboarding during a SOC 2 examination.
Displaying items 10-18 of 19 in total