Legal information
Security and disclosure policy
Last updated: 20 January 2026 — the French version is the legally binding one
Our commitment
At Wapply we take very seriously the security of the sensitive data you entrust to us to manage your career.
1. Data protection and encryption
Encryption in transit: all data exchanged between your app, our servers and third-party sites is protected by TLS/SSL (HTTPS).
Encryption at rest: your sensitive data (CV, contact details) is stored in encrypted databases (AES-256 standard).
2. Security of third-party credentials
Wapply generates a complex, unique password for every account created on a careers site.
- Those passwords are held in an encrypted digital vault.
- They are used only by our automated agents when signing in.
- They are never visible in plain text to Wapply staff.
3. Security of the email alias (Wapply Mail)
The email address generated for your applications is covered by strict measures:
- Automated processing: emails are read by software (parsers) to update statuses.
- Isolation: each user has an isolated environment so that no data can cross over.
- Human access: our engineers access email content only where absolutely necessary (critical technical debugging) and under strict audit logging.
4. Responsible vulnerability disclosure
Wapply does not run a bug bounty programme (financial reward), but we encourage security researchers to report any potential flaw to us responsibly.
How to report: if you identify a vulnerability, please send an email to contact@wapply.io including:
- a detailed description of the flaw;
- the steps to reproduce it (proof of concept).
Our commitment:
- we will review your report promptly;
- we will not pursue researchers who act in good faith, do not steal user data and do not disrupt the service;
- we ask you to keep the flaw confidential until it has been fixed.