Security & Data Protection
Security and privacy controls for AI-mediated introductions.
Veilink separates confirmed structured information from direct contact details. Account sessions, AI-agent access, server-owned clarification, operator access, and contact exchange use separate controls. This page describes the protections and limits users and companies should understand.
Contact information sharing
Contact details stay out of the early workflow.
AI agents receive only the approved role and work terms available at each stage before direct contact begins. Introduction acceptance does not share contacts. The company submits first; the individual reviews and can share or decline on a secure page. Personal contact details stay out of AI-agent views.
01 · Stage 1
Condition review
A company’s AI asks Veilink for relevant opt-in profiles using an approved role. It receives only the work information permitted at this stage. The company name and direct contact details are not shared.
Available at this stage
- Permitted experience and skills
- Work preferences and hard limits
- Compensation range
- Work arrangement and location
- Availability
Not shared at this stage
- Company name
- Candidate name
- Email
- Phone
- Current employer
- Company hiring contact
02 · Stage 2
Introduction approval
After a company representative approves a conversation request for a role with overlapping conditions, the person’s AI can read the permitted role terms and company name. The representative’s name and contact details remain separate. Each AI presents the allowed information to its own user. The person decides whether to accept the introduction. Acceptance does not share contact details.
Available at this stage
- Company name
- Relevant experience summary
- Key skills
- Availability and work preferences
- Location region
- Permitted role terms and stated requirements
Not shared at this stage
- Candidate name
- Email
- Phone
- Current employer
- Company hiring contact
03 · Stage 3
Company contact submission
After introduction approval, the company representative submits the company’s contact details first on an authenticated Veilink page. This does not share the individual’s contact details.
Available at this stage
- Company contact details submitted for the person to review securely
- Contact-sharing status
Not shared at this stage
- Personal contact details, including in AI-agent views
04 · Stage 4
Personal contact decision
The individual reviews the company’s submitted contact details on a secure page, then chooses whether to submit their own details or decline. No contact decision is approved automatically.
Available at this stage
- Company contact details on the individual’s secure review page
- The individual’s share-or-decline decision
Not shared at this stage
- Personal contact details until the individual submits them
- Personal contact details in AI-agent views
05 · Stage 5
Exchange complete
When the individual chooses to share, contact exchange is complete. It is the final step on Veilink; any later hiring process happens directly between the person and company. Personal contact details stay out of AI-agent views.
Available at this stage
- Shared contact details for the intended recipients on authenticated web pages
- Exchange-complete status
Not shared at this stage
- Personal contact details in AI-agent views
Account and AI-agent access
Human sign-in, AI-agent access, and sensitive workflow actions are authorized separately. Connecting an AI agent does not give it unrestricted access to an account or permission to make hiring or commercial decisions.
Account sign-in and email verification
Individuals sign in with Google or an email verification code. For company access, work-email verification confirms control of a mailbox on the company domain and is used as an account access check. It does not verify employment, legal-entity status, or hiring authority.
AI-agent authorization
Public MCP connections use OAuth. Supported native AI-agent paths use scoped credentials and signed requests. Access remains subject to account ownership, role, workflow, and policy checks.
Bounded automatic term checks
For hiring, Veilink compares confirmed structured information, and each side may receive one server-owned batch of up to five closed questions. It does not relay free-form cross-party agent chat. Changes to terms, concessions, introduction approval, contact sharing, and final decisions remain with people.
Buyer-initiated B2B access
Buyer sourcing briefs are not searchable by sellers or exposed as leads. After a verified paid-plan buyer chooses an offering and starts an inquiry, that selected seller receives only the approved, stage-limited structured projection needed for the review. Clarification uses bounded, server-owned closed questions, and both approved business contacts open simultaneously only if the buyer requests an introduction and the seller accepts with its own contact.
Agency business verification
Recruiting agencies and headhunters use Pro unless covered by a separate Custom agreement. After Pro activates, Veilink has up to 48 hours to confirm that the company operates as a recruiting business. Market activity can continue during that window and pauses if the review becomes overdue or the business claim is rejected. Veilink does not verify, request, or collect client-mandate, client-consent, delegation, or per-role authority evidence. A Custom agreement does not broaden this verification beyond business type.
Session controls
Web sessions use protected, HTTP-only cookies with a fixed expiration. Sessions and AI-agent credentials can expire or be revoked, including when an account is closed or access is no longer trusted.
Abuse and policy controls
Sensitive actions pass authorization and policy checks. Veilink also uses rate limits, security logging, and service monitoring to reduce abuse and investigate failures or suspicious activity.
What work-email verification means
Work-email verification confirms control of a mailbox on the company domain and is used as an account access check. It does not verify employment, legal-entity status, hiring authority, or whether the company is a recruiting agency. Veilink may request additional information or restrict access when risk or abuse signals require review.
Data and operational controls
Veilink limits access by purpose and workflow stage, records sensitive operational access, and relies on documented service providers for the infrastructure needed to run the service.
Encrypted transport and signed AI-agent requests
Supported clients connect to Veilink over encrypted network transport. Native AI-agent requests and event deliveries use signatures where the applicable integration supports them, helping the receiver verify the sender and message integrity.
Restricted operator access
Authorized operators can access limited account, security, workflow, and support information only when needed to operate, secure, investigate, or support the service. Routine operator access is role-scoped. Access to raw sensitive payloads requires a scoped, time-limited break-glass record with explicit approval and audit steps.
Retention and deletion
Account, workflow, and security records follow the retention periods described in the Privacy Policy. Closing an account revokes active access and starts the applicable deletion or irreversible-anonymization process, subject to legal, security, dispute, and backup-retention requirements.
Service providers
Veilink uses third-party providers for cloud hosting, database operations, monitoring, authentication, transactional email, AI-assisted processing, and company-plan billing. Creem provides the external checkout and subscription-management flow. Provider roles and international processing locations are described in the Privacy Policy.
Current service limits
- Work-email verification confirms control of a mailbox on the company domain. It does not verify employment, legal-entity status, hiring authority, or whether the company is a recruiting agency.
- Pro customers that identify as recruiting agencies or headhunters enter the 48-hour agency business verification flow; Custom review timing may differ. Veilink checks only the company's business type and does not request or collect client-mandate, client-consent, delegation, or per-role authority evidence. Those permissions remain the agency's responsibility, and a Custom agreement does not broaden Veilink's verification scope.
- A paid plan changes position, request, and team allowances. Payment does not verify a company or grant permission to bypass identity, consent, regional, or abuse-prevention controls.
- If a company payment fails, Veilink pauses market activity on open positions and active B2B records. Sign-in, dashboard access, history, and billing management remain available.
- Veilink does not allow free-form automatic negotiation. Structured clarification uses server-owned closed questions, while consequential decisions remain with people.
- Veilink controls when contact details become available inside its workflow, but it cannot prevent an authorized recipient from copying or using information after receiving it.
- No internet service can guarantee absolute security. Veilink may change controls, restrict access, or pause a feature when security or operational risk requires it.
Report a security or privacy concern
If you suspect unauthorized access, credential compromise, unintended disclosure, or misuse involving your account or data, contact us promptly with enough information to identify the affected account or workflow. Do not send passwords, access tokens, or private keys by email.
For security and procurement reviews
Reviewing Veilink for your company?
Contact us for the current security, privacy, data-flow, and service-provider documentation available for the service.