# Security and your data

> How your account, your job board logins, and your contacts are protected.

## Your account

Every account is isolated. Nothing on your account (runs, contacts, candidates, do-not-contact entries, tickets) is visible to any other account, and every request is checked against the account you belong to.

## Job board logins

A board password is encrypted at rest and write-only: nothing in the product can display it again. When Tenure's sourcing technology uses it to work a run, the use is recorded in your activity log with the run, the time, and the reason. Account admins can read that log at any time.

## Activity log

Every change a user makes on the account is recorded, with secrets stripped. See [User activity audit](/documentation/reports/user-activity).

## Candidates and contacts

Contact details are unlocked only after a person replies interested. Anyone who opts out is recorded and never messaged again. Your do-not-contact list is honoured by every channel.

## Sessions

Sessions expire after a period of inactivity. When one does, you are returned to the sign-in page with a note, and nothing you had open is changed.
