Security
Security commitments.
Last updated August 25, 2026.
This page states how Admitted is designed to protect applicant and member data, in plain language and without exaggeration.
Before opening. Applications are not open and no member accounts, mailboxes, or member data exist yet. The controls below are design commitments of the system being built; this page will be updated to describe operating controls before any member data is collected.
Account authentication and recovery.
Accounts are built around passkeys first, with authenticator-app TOTP and single-display recovery codes as fallback. A password alone is never sufficient to activate or administer a mailbox: applicants who choose a password path must add TOTP before submitting sensitive material.
Account recovery requires a verified external recovery email that is not an
@admitted.law address, plus a second approved recovery factor, so a
lost mailbox is never the only path back into the account that controls it.
Application document handling.
Resumes and application documents will be uploaded directly to private, access-controlled object storage (Cloudflare R2) using short-lived signed URLs and server-generated object keys. Nothing will ever be served from a public bucket.
Every uploaded file is validated and scanned for malware before any reviewer can open it, and documents are deleted on the schedule published in the Privacy Notice. Reviewers see documents only through access-controlled, audited routes.
The mailbox-provider boundary.
Member mail will be hosted by a contracted mailbox provider, with each member's mailbox as an isolated account. Admitted's application systems will manage membership, billing, and verification status; they will not store or casually access mailbox contents, and the provider must demonstrate that no member can send as another member. No provider is contracted yet.
The provider and its supported access methods will be named in the member dashboard under mailbox setup once a contract exists. Ordinary email is not end-to-end encrypted, and Admitted does not claim otherwise.
Administrative access and audit.
Staff access will follow least privilege: reviewers and administrators get the narrowest access their role requires, sensitive values are stored protected and revealed only deliberately, and administrative actions are recorded in append-only audit logs with actor, action, and timestamp. Secrets, license numbers, resume contents, and personal values are kept out of application logs.
Dependency and secret hygiene.
Dependencies are pinned through a lockfile and reviewed for known vulnerabilities before release. Secrets live in the deployment platform's managed configuration, never in source control, and are rotated when staff access changes or exposure is suspected. Configuration is validated at startup, and production refuses to start in an unsafe combination rather than running open.
Incident notification.
If an incident ever affects applicant or member data, Admitted will investigate
promptly, notify affected people and any required regulators as the law requires,
and say plainly what is known, what is not yet known, and what to do - without
minimizing. Status will be communicated through a channel that does not depend
solely on admitted.law infrastructure, so an outage cannot silence
the notice.
Responsible disclosure.
A monitored security route for vulnerability reports and responsible disclosure will be published on the Contact page before applications open - Admitted does not publish a reporting address before someone is actually reading it. When it exists: Admitted will acknowledge good-faith reports and will not pursue researchers who follow this policy - test only against your own account, do not access, modify, or retain another person's data, do not degrade the service, and give Admitted a reasonable chance to fix an issue before publishing it.
A separate monitored route for impersonation, phishing, and mail-abuse reports will be published alongside it. Do not include privileged client material or identity documents in any report.
Planned vendors.
The platform Admitted is built on. Each vendor below will process data on Admitted's behalf once applications open; none processes applicant or member data today, because none exists.
| Vendor | Role |
|---|---|
| Vercel | Application hosting and deployment. |
| Cloudflare | DNS, private object storage (R2), and bot mitigation (Turnstile). |
| Neon | Managed PostgreSQL database. |
| Stripe | Payment processing. Card numbers never touch Admitted servers. |
More vendors - including the mailbox provider, identity-proofing provider, and document scanner - have not been selected. The full subprocessor list will accompany the Privacy Notice and will be updated before any new subprocessor begins processing.
What this page does not claim.
Admitted holds no compliance certifications and claims none. This page makes no absolute promises: no system is beyond compromise, ordinary email is not end-to-end encrypted, and every claim here is limited to what is actually built and operated. What membership verification does and does not mean is published on the Standards page.