Security
WackoWave OS handles resumes, identity-adjacent documents, and hiring data for jobseekers, consultants, and employers. Security is treated as a product requirement, not an afterthought.
1. Infrastructure
The Platform runs on Google Cloud / Firebase infrastructure. Data is encrypted in transit (TLS) and at rest. Authentication is handled through LinkedIn OAuth and Firebase Authentication rather than storing raw passwords for social sign-in users.
2. Access controls
Access to candidate documents, verification results, and submission history is restricted by role — recruiters, employers, and candidates each see only what their permissions allow. Internal access to production data is limited to authorized WackoWave personnel.
3. Document verification
Our 4-layer document review (timeline integrity, growth trajectory, compensation logic, and experience depth) is designed to flag inconsistencies in submitted materials. It is a decision-support signal for recruiters, not an identity-verification or background-check service.
4. Data handling
- Candidate visibility is controlled by the candidate, including a "ghost mode" that hides a profile from employer search.
- Submission and outreach actions are logged to keep an audit trail of what was sent, when, and to whom.
- Data is retained only as long as needed to operate the Platform or meet legal obligations, and can be deleted on request.
5. Reporting a security issue
If you believe you've found a security vulnerability in WackoWave OS, please report it to hello@wackowave.solutions with as much detail as possible. We aim to acknowledge reports promptly and do not currently offer a paid bug bounty.
6. Compliance
WackoWave is an early-stage platform and does not yet hold formal certifications (e.g. SOC 2, ISO 27001). This page will be updated as our compliance posture develops.
WackoWave